commit
6c2794a2984f4c17a58117a68703cc7640f01c5a upstream.
Instead of using data from stack for DMA in hidinput_get_battery_property(),
allocate the buffer dynamically.
Reported-by: Richard Ryniker <ryniker@alum.mit.edu>
Reported-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Jiri Kosina <jkosina@suse.cz>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
{
struct hid_device *dev = container_of(psy, struct hid_device, battery);
int ret = 0;
{
struct hid_device *dev = container_of(psy, struct hid_device, battery);
int ret = 0;
switch (prop) {
case POWER_SUPPLY_PROP_PRESENT:
switch (prop) {
case POWER_SUPPLY_PROP_PRESENT:
break;
case POWER_SUPPLY_PROP_CAPACITY:
break;
case POWER_SUPPLY_PROP_CAPACITY:
+
+ buf = kmalloc(2 * sizeof(__u8), GFP_KERNEL);
+ if (!buf) {
+ ret = -ENOMEM;
+ break;
+ }
ret = dev->hid_get_raw_report(dev, dev->battery_report_id,
ret = dev->hid_get_raw_report(dev, dev->battery_report_id,
dev->battery_report_type);
if (ret != 2) {
if (ret >= 0)
ret = -EINVAL;
dev->battery_report_type);
if (ret != 2) {
if (ret >= 0)
ret = -EINVAL;
buf[1] <= dev->battery_max)
val->intval = (100 * (buf[1] - dev->battery_min)) /
(dev->battery_max - dev->battery_min);
buf[1] <= dev->battery_max)
val->intval = (100 * (buf[1] - dev->battery_min)) /
(dev->battery_max - dev->battery_min);
break;
case POWER_SUPPLY_PROP_MODEL_NAME:
break;
case POWER_SUPPLY_PROP_MODEL_NAME: