From nobody Fri Sep 25 00:40:31 2026 Received: from mailout4.samsung.com (mailout4.samsung.com [203.254.224.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B4377488D97 for ; Fri, 18 Sep 2026 10:32:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=203.254.224.34 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789727577; cv=none; b=e1B5D4iI5t4xxK10E288HQ6tTIxBfybiBdXIfqJliRRc17XoLQvE0ZX89WkF/+kixMP+nX2NfFM9HpxwyC54HMQYY0IjbGE2n21bVgfB6QS5rz2/ZCN0RRk5kBKTDEkwwI06zCstLpJ2c3Mko5+fwD0xV1w+T0NblxE5h/V9uBc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789727577; c=relaxed/simple; bh=aBbgqH7iUq0TjB4Ev/jowkIaT+djFNlSXLBGCQgd3oc=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version:Content-Type: References; b=RkHza2nmoYrldyLfhQ9ShLlDLX9DUTkKU76KdXw3vTzsqB/HpvpfpeFUEIFTyn53Cw9E5lGY774i3Wkif8BPNz1w3Xuzev6v3JF4qM2c6I5agJsxuNxodvA9qr25gPmFoXS2KayXlmYMs0WQm5FXuqWM5+5Nn4UdGew4Q0LwCpo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=samsung.com; spf=pass smtp.mailfrom=samsung.com; dkim=pass (1024-bit key) header.d=samsung.com header.i=@samsung.com header.b=SPcxMw5W; arc=none smtp.client-ip=203.254.224.34 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=samsung.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=samsung.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=samsung.com header.i=@samsung.com header.b="SPcxMw5W" Received: from epcas5p2.samsung.com (unknown [182.195.41.40]) by mailout4.samsung.com (KnoxPortal) with ESMTP id 20260918103251epoutp0493f3dff36454b16660e1f5e3f733f473~WY75nPHCC2711827118epoutp04T for ; Fri, 18 Sep 2026 10:32:51 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 mailout4.samsung.com 20260918103251epoutp0493f3dff36454b16660e1f5e3f733f473~WY75nPHCC2711827118epoutp04T DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=samsung.com; s=mail20170921; t=1789727571; bh=G/fO5FlRuEocHNQCmGx71FcmWAbH2HBbMkGQ6JIB1n0=; h=From:To:Cc:Subject:Date:References:From; b=SPcxMw5Wj2fUsgclY0yoANRSZ/kKgABR9Eo7W1UEkrf0wbY5NJ3thqoAzBxXHWus8 0lo6eE2UKl2INlHUG+1Tk4x2VjsK4SYn9I2Hhm1t1lIckVvSKK/DZGilqPQEZAkj3t otCuc5JQ7dLDWLP5NLyvSGo+p/Vck+W+PKO6Jo80= Received: from epsnrtp04.localdomain (unknown [182.195.42.156]) by epcas5p1.samsung.com (KnoxPortal) with ESMTPS id 20260918103250epcas5p12ea5e88ac36103898712ab45eeedd8cf~WY75Fn9oV2545625456epcas5p1n; Fri, 18 Sep 2026 10:32:50 +0000 (GMT) Received: from epcas5p4.samsung.com (unknown [182.195.38.89]) by epsnrtp04.localdomain (Postfix) with ESMTP id 4hmTTs67L8z6B9m8; Fri, 18 Sep 2026 10:32:49 +0000 (GMT) Received: from epsmtip2.samsung.com (unknown [182.195.34.31]) by epcas5p4.samsung.com (KnoxPortal) with ESMTPA id 20260918103249epcas5p49c9b4bf6fd60c28f5f09f0b7b69828b6~WY73wwcaF2951229512epcas5p4l; Fri, 18 Sep 2026 10:32:49 +0000 (GMT) Received: from vega.samsungds.net (unknown [107.108.73.84]) by epsmtip2.samsung.com (KnoxPortal) with ESMTPA id 20260918103246epsmtip21d5c7565d73ad5927a1fd761e7fb625e~WY70toq-q0288802888epsmtip2s; Fri, 18 Sep 2026 10:32:45 +0000 (GMT) From: Selvarasu Ganesan To: vkoul@kernel.org, neil.armstrong@linaro.org, mani@kernel.org, krzk@kernel.org, peter.griffin@linaro.org, alim.akhtar@samsung.com, pritam.sutar@samsung.com, andre.draszik@linaro.org, kernel@lvkasz.us, pengpeng@iscas.ac.cn, selvarasu.g@samsung.com, linux-phy@lists.infradead.org, linux-arm-kernel@lists.infradead.org, linux-samsung-soc@vger.kernel.org, linux-kernel@vger.kernel.org Cc: jh0801.jung@samsung.com, h10.kim@samsung.com, dh10.jung@samsung.com, akash.m5@samsung.com, hongpooh.kim@samsung.com, eomji.oh@samsung.com, shijie.cai@samsung.com, muhammed.ali@samsung.com, thiagu.r@samsung.com Subject: [PATCH v2] phy: exynos5-usbdrd: Use dynamic phy_cfg size to prevent OOB access Date: Fri, 18 Sep 2026 16:01:47 +0530 Message-Id: <20260918103147.2628614-1-selvarasu.g@samsung.com> X-Mailer: git-send-email 2.17.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CMS-MailID: 20260918103249epcas5p49c9b4bf6fd60c28f5f09f0b7b69828b6 X-Msg-Generator: CA Content-Type: text/plain; charset="utf-8" CMS-TYPE: 105P cpgsPolicy: CPGSC10-542,Y X-CFilter-Loop: Reflected X-CMS-RootMailID: 20260918103249epcas5p49c9b4bf6fd60c28f5f09f0b7b69828b6 References: The probe loop currently iterates using EXYNOS5_DRDPHYS_NUM (2), creating both UTMI and PIPE3 PHY instances regardless of the SoC capability. Several SoCs (Exynos2200, Exynos7870, Exynos850, Exynos990, and ExynosAutoV920) provide phy_cfg arrays containing only a single element. On these SoCs, when the loop reaches index 1, the driver reads past the end of the rodata array, populating the second PHY instance with garbage data. Since the configuration structure contains critical function pointers (phy_isol, phy_init, set_refclk), any subsequent access to this PHY instance via exynos5_usbdrd_phy_xlate could result in a kernel oops. Fix this by adding 'n_phy_cfg' to struct exynos5_usbdrd_phy_drvdata to store the actual size of the phy_cfg array for each SoC. Update the probe loop and the xlate function to bound their access against this value instead of the hardcoded EXYNOS5_DRDPHYS_NUM. Assisted-by: LLM Signed-off-by: Selvarasu Ganesan Tested-by: =C5=81ukasz Lebiedzi=C5=84ski Reviewed-by: Alim Akhtar Reviewed-by: Andr=C3=A9 Draszik Reviewed-by: Peter Griffin --- Changes in V2: - Updated 'Assisted-by' tag to follow the proper kernel documentation format. - Link to v1: https://lore.kernel.org/all/20260831070309.158069-1-selvarasu.g@samsung.c= om/ --- drivers/phy/samsung/phy-exynos5-usbdrd.c | 17 +++++++++++++++-- 1 file changed, 15 insertions(+), 2 deletions(-) diff --git a/drivers/phy/samsung/phy-exynos5-usbdrd.c b/drivers/phy/samsung= /phy-exynos5-usbdrd.c index 087d552eb511..f10cf7b6e0aa 100644 --- a/drivers/phy/samsung/phy-exynos5-usbdrd.c +++ b/drivers/phy/samsung/phy-exynos5-usbdrd.c @@ -477,6 +477,7 @@ struct exynos5_usbdrd_phy_config { =20 struct exynos5_usbdrd_phy_drvdata { const struct exynos5_usbdrd_phy_config *phy_cfg; + int n_phy_cfg; const struct exynos5_usbdrd_phy_tuning **phy_tunes; const struct phy_ops *phy_ops; const char * const *clk_names; @@ -1173,7 +1174,7 @@ static struct phy *exynos5_usbdrd_phy_xlate(struct de= vice *dev, { struct exynos5_usbdrd_phy *phy_drd =3D dev_get_drvdata(dev); =20 - if (WARN_ON(args->args[0] >=3D EXYNOS5_DRDPHYS_NUM)) + if (WARN_ON(args->args[0] >=3D phy_drd->drv_data->n_phy_cfg)) return ERR_PTR(-ENODEV); =20 return phy_drd->phys[args->args[0]].phy; @@ -2021,6 +2022,7 @@ static const char * const exynos5_regulator_names[] = =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos2200_usb32drd_phy =3D= { .phy_cfg =3D phy_cfg_exynos2200, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos2200), .phy_ops =3D &exynos2200_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS2200_PHY_CTRL_USB20, .clk_names =3D exynos5_clk_names, @@ -2034,6 +2036,7 @@ static const struct exynos5_usbdrd_phy_drvdata exynos= 2200_usb32drd_phy =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos5420_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos5, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos5), .phy_ops =3D &exynos5_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS5_USBDRD_PHY_CONTROL, .pmu_offset_usbdrd1_phy =3D EXYNOS5420_USBDRD1_PHY_CONTROL, @@ -2047,6 +2050,7 @@ static const struct exynos5_usbdrd_phy_drvdata exynos= 5420_usbdrd_phy =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos5250_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos5, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos5), .phy_ops =3D &exynos5_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS5_USBDRD_PHY_CONTROL, .clk_names =3D exynos5_clk_names, @@ -2059,6 +2063,7 @@ static const struct exynos5_usbdrd_phy_drvdata exynos= 5250_usbdrd_phy =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos5433_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos5, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos5), .phy_ops =3D &exynos5_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS5_USBDRD_PHY_CONTROL, .pmu_offset_usbdrd1_phy =3D EXYNOS5433_USBHOST30_PHY_CONTROL, @@ -2072,6 +2077,7 @@ static const struct exynos5_usbdrd_phy_drvdata exynos= 5433_usbdrd_phy =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos7_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos5, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos5), .phy_ops =3D &exynos5_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS5_USBDRD_PHY_CONTROL, .clk_names =3D exynos5_clk_names, @@ -2084,6 +2090,7 @@ static const struct exynos5_usbdrd_phy_drvdata exynos= 7_usbdrd_phy =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos7870_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos7870, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos7870), .phy_tunes =3D exynos7870_tunes, .phy_ops =3D &exynos7870_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS5_USBDRD_PHY_CONTROL, @@ -2097,6 +2104,7 @@ static const struct exynos5_usbdrd_phy_drvdata exynos= 7870_usbdrd_phy =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos850_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos850, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos850), .phy_ops =3D &exynos850_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOS5_USBDRD_PHY_CONTROL, .clk_names =3D exynos5_clk_names, @@ -2125,6 +2133,7 @@ static const struct exynos5_usbdrd_phy_tuning *exynos= 990_tunes[PTS_MAX] =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynos990_usbdrd_phy =3D { .phy_cfg =3D phy_cfg_exynos850, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynos850), .phy_ops =3D &exynos850_usbdrd_phy_ops, .phy_tunes =3D exynos990_tunes, .pmu_offset_usbdrd0_phy =3D EXYNOS990_PHY_CTRL_USB20, @@ -2661,6 +2670,7 @@ static const struct phy_ops exynosautov920_usb31drd_c= ombo_ssphy_ops =3D { static const struct exynos5_usbdrd_phy_drvdata exynosautov920_usb31drd_combo_ssphy =3D { .phy_cfg =3D usb31drd_phy_cfg_exynosautov920, + .n_phy_cfg =3D ARRAY_SIZE(usb31drd_phy_cfg_exynosautov920), .phy_ops =3D &exynosautov920_usb31drd_combo_ssphy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOSAUTOV920_PHY_CTRL_USB31, .clk_names =3D exynos5_clk_names, @@ -2691,6 +2701,7 @@ exynos5_usbdrd_phy_config usbdrd_hsphy_cfg_exynosauto= v920[] =3D { static const struct exynos5_usbdrd_phy_drvdata exynosautov920_usbdrd_combo_hsphy =3D { .phy_cfg =3D usbdrd_hsphy_cfg_exynosautov920, + .n_phy_cfg =3D ARRAY_SIZE(usbdrd_hsphy_cfg_exynosautov920), .phy_ops =3D &exynosautov920_usbdrd_combo_hsphy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOSAUTOV920_PHY_CTRL_USB20, .clk_names =3D exynos5_clk_names, @@ -2719,6 +2730,7 @@ static const struct exynos5_usbdrd_phy_config phy_cfg= _exynosautov920[] =3D { =20 static const struct exynos5_usbdrd_phy_drvdata exynosautov920_usbdrd_phy = =3D { .phy_cfg =3D phy_cfg_exynosautov920, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_exynosautov920), .phy_ops =3D &exynosautov920_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D EXYNOSAUTOV920_PHY_CTRL_USB20, .clk_names =3D exynos5_clk_names, @@ -2895,6 +2907,7 @@ static const char * const gs101_regulator_names[] =3D= { =20 static const struct exynos5_usbdrd_phy_drvdata gs101_usbd31rd_phy =3D { .phy_cfg =3D phy_cfg_gs101, + .n_phy_cfg =3D ARRAY_SIZE(phy_cfg_gs101), .phy_tunes =3D gs101_tunes, .phy_ops =3D &gs101_usbdrd_phy_ops, .pmu_offset_usbdrd0_phy =3D GS101_PHY_CTRL_USB20, @@ -3052,7 +3065,7 @@ static int exynos5_usbdrd_phy_probe(struct platform_d= evice *pdev) =20 dev_vdbg(dev, "Creating usbdrd_phy phy\n"); =20 - for (i =3D 0; i < EXYNOS5_DRDPHYS_NUM; i++) { + for (i =3D 0; i < drv_data->n_phy_cfg; i++) { struct phy *phy =3D devm_phy_create(dev, NULL, drv_data->phy_ops); =20 if (IS_ERR(phy)) --=20 2.17.1