aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJiri Slaby <jslaby@suse.cz>2014-04-14 10:46:50 -0400
committerLinus Torvalds <torvalds@linux-foundation.org>2014-04-17 15:23:06 -0400
commita94cdd1f4d30f12904ab528152731fb13a812a16 (patch)
tree2b1b076a076e9edecfd52d2a3b784a25bf1e4260
parentc9eaa447e77efe77b7fa4c953bd62de8297fd6c5 (diff)
Char: ipmi_bt_sm, fix infinite loop
In read_all_bytes, we do unsigned char i; ... bt->read_data[0] = BMC2HOST; bt->read_count = bt->read_data[0]; ... for (i = 1; i <= bt->read_count; i++) bt->read_data[i] = BMC2HOST; If bt->read_data[0] == bt->read_count == 255, we loop infinitely in the 'for' loop. Make 'i' an 'int' instead of 'char' to get rid of the overflow and finish the loop after 255 iterations every time. Signed-off-by: Jiri Slaby <jslaby@suse.cz> Reported-and-debugged-by: Rui Hui Dian <rhdian@novell.com> Cc: Tomas Cech <tcech@suse.cz> Cc: Corey Minyard <minyard@acm.org> Cc: <openipmi-developer@lists.sourceforge.net> Signed-off-by: Corey Minyard <cminyard@mvista.com> Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
-rw-r--r--drivers/char/ipmi/ipmi_bt_sm.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/drivers/char/ipmi/ipmi_bt_sm.c b/drivers/char/ipmi/ipmi_bt_sm.c
index f5e4cd7617f6..61e71616689b 100644
--- a/drivers/char/ipmi/ipmi_bt_sm.c
+++ b/drivers/char/ipmi/ipmi_bt_sm.c
@@ -352,7 +352,7 @@ static inline void write_all_bytes(struct si_sm_data *bt)
352 352
353static inline int read_all_bytes(struct si_sm_data *bt) 353static inline int read_all_bytes(struct si_sm_data *bt)
354{ 354{
355 unsigned char i; 355 unsigned int i;
356 356
357 /* 357 /*
358 * length is "framing info", minimum = 4: NetFn, Seq, Cmd, cCode. 358 * length is "framing info", minimum = 4: NetFn, Seq, Cmd, cCode.