From nobody Mon Sep 28 07:18:11 2026 Received: from out203-205-221-236.mail.qq.com (out203-205-221-236.mail.qq.com [203.205.221.236]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 33DC93CE4A3 for ; Tue, 25 Aug 2026 09:08:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=203.205.221.236 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787648888; cv=none; b=N/uS4yprWPONpUvBWBtt8fIYc3NLwFico6oPAjBlNvOG6Sk/wP9Uot1FbVZe+EgTZFzl0xGsiPoJRsNdiBpDReH8qKOYEcwmS4OummPgBXVyz6KZ2RzG76o+lKw5c4EHqdp0MBCEL6VfR9qxBHBTMu4O9NpC3sKF+0pfdAE87wc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787648888; c=relaxed/simple; bh=tQFMZ2FOMK8RhmO96wY7g0uKY64ztu7r6NCW4GDoRDM=; h=Message-ID:Date:MIME-Version:To:Cc:From:Subject:Content-Type; b=p9P8p2T7BYN/byRtUFgDdDDiqP9+8IWBK5CScUNbJg6/V+uQuDMXnxzOcfg7BnVfCYyiZI7D7+coWxxPZT0W17aY5qdMZSNFgsk/d0Yc5pKhDEfDwyqNghvT8G1uGdOucGlREpoGgpcU5/GL0bqiDbNxabftDgwyXHvMhfJBPW4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com; spf=pass smtp.mailfrom=qq.com; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b=Vl6CPgqq; arc=none smtp.client-ip=203.205.221.236 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=qq.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=qq.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=qq.com header.i=@qq.com header.b="Vl6CPgqq" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qq.com; s=s201512; t=1787648877; bh=tQFMZ2FOMK8RhmO96wY7g0uKY64ztu7r6NCW4GDoRDM=; h=Date:To:Cc:From:Subject; b=Vl6CPgqqvaaiLTK3HqesoN0OtnUsG54DUP7YM5OvetpnLuCKsJc5rXLLyw4iPO5Ml BrxvkmHGOtuMhQV0b2siokWYGw1E/FoaJrobsLQErxpQPwKM7nOE+QKfLIsSnyulyn 4L2vYKEQ1fXXlwaX3lkxQ8/Vh+y4VG27vgTiPiyY= Received: from [192.168.255.10] ([111.206.145.19]) by newxmesmtplogicsvrszc56-0.qq.com (NewEsmtp) with SMTP id 1F798C09; Tue, 25 Aug 2026 17:07:55 +0800 X-QQ-mid: xmsmtpt1787648875td67o8ou2 Message-ID: X-QQ-XMAILINFO: MllZffuBkEb5z+fflsBz/VsUP1BZNpaMt0WonzVZwpdFjTSwLyyrarXIwpYHOq Vh+tyMkG4KT4bXR1W5+uGO9y8nS4rLqpWQlUOsoKPCSh4xXAaqqR5kM0TvuqGc3M3DBxODSUNPHB MRFsrWM3QZOXjLQUKT7+d4fqUF9GWW/fFm1XZO62rEqp6xYm2V3RblO/irkuM+0WNbL5y7UPVomo DEdkVh5Npna/YpONmSs+rMC63P4VfGJq2P7+4wuvc2KJ29ttLPIygZHYhWUSKiTpK+JOpWKdJ+RN q/BIsftSmE33kyShdZb9ttBE+ASD2koKl7Dace93OFbKmTUO4LAr3/cIksqvJrrO15Z2aL3s2pdB P767a8x4dghlZ2f8nm9lTZCQwoCisbZFSCFRoZzfxxoJcRAdw5GLuypqRof94cxd2sxj6H3a4rO/ 7bfjdIt7vz/5FftYU1jUfjbLpVoeREojqcU4dwENJlFAo9RmSo5ZrPTeTjRYetVCx+B0uYg3Px4l 9XGNJArBSK+louHStkh30r95ipgqtfupvuerDPLrMzUx9VmOJMnVRyYfKJ/AQNfXh5e9sEp7/jtN cr9Ui+xl1sOOKIS+7f8GViwyXpkx89e3sqyirJxoPIzc/W0jgsVjBLQHnpxB19aOZR/QcZQqBzXi f1K7lvaLm4QQLDE/yTHwRwls6Rb2445oajZ7Ktv1VGjSpJ5osvY5cvonFVVTn1yW0aJhqys9xvd4 IDP6jvnsdCylaYp6DHUHgYHVRj9MuhxCpLdAaKK2YD2oU6ylF3bIFB/IsGcZOPE6ILeP5H393Bgk owrWYgIfPkbPzCobN8hPrZVlkVf/V5J2DLeq6T9iKqUTXmbTHM9Wk0vUSJlGgF5uhvOjoxctJO6I 53HEyZMZR/D6K+xdRWE4zQlAVI81dinQI+uQ8GFUViOqRe5J/YjkFVoxg1nYOqgG/YN0qz4SK9Fq JFsEZPV3dNEozczsnUAQKJDzccRbImd95i81U+9EYNsJO4nZ9/xl+tSKMz9FfggXVK8hImNkIHe2 10KajJ7S2ZEnKQ96s3zk9qzqe1DFOCHwniiXMRkx6cy44VhR+Dxg+eHyugGUWcz8sJgshhdE2C4U zNc1ek4AdESGVm3QWr+NiHuBcWsg== X-QQ-XMRINFO: MSVp+SPm3vtSI1QTLgDHQqIV1w2oNKDqfg== X-OQ-MSGID: <9f24c96e-ef7e-49f7-aa8e-6ea563969fa9@qq.com> Date: Tue, 25 Aug 2026 17:07:54 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird To: abbotti@mev.co.uk, hsweeten@visionengravers.com Cc: gregkh@linuxfoundation.org, u.kleine-koenig@baylibre.com, linux-kernel@vger.kernel.org From: Yang Zi <2959243019@qq.com> Subject: [PATCH] comedi: addi_apci_3xxx: fix subdevice count underallocation Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable In apci3xxx_auto_attach(), the number of subdevices is computed with =C2=A0 =C2=A0 n_subdevices =3D (board->ai_n_chan ? 0 : 1) + board->has_ao += ... The ternary is inverted: when the board has analog input channels (ai_n_chan !=3D 0), it counts 0 instead of 1, so the AI subdevice that is actually created is not accounted for. As a result comedi_alloc_subdevices() allocates one entry too few, and the later subdevice initialization (notably the TTL Digital I/O subdevice, which is populated last) writes past the end of the allocated array, causing a slab out-of-bounds write. Flip the ternary to count 1 when ai_n_chan is non-zero and 0 otherwise, matching the subdevice creation order in the function. Signed-off-by: Yang Zi <2959243019@qq.com> Reviewed-by: Ian Abbott --- diff --git a/drivers/comedi/drivers/addi_apci_3xxx.c b/drivers/comedi/drive= rs/addi_apci_3xxx.c index 695cce103177..1dcda82d9503 100644 --- a/drivers/comedi/drivers/addi_apci_3xxx.c +++ b/drivers/comedi/drivers/addi_apci_3xxx.c @@ -787,7 +787,7 @@ static int apci3xxx_auto_attach(struct comedi_device *d= ev, =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0dev->irq =3D pcidev->irq; =C2=A0 =C2=A0 =C2=A0} =C2=A0 -=C2=A0 =C2=A0 n_subdevices =3D (board->ai_n_chan ? 0 : 1) + board->has_ao + +=C2=A0 =C2=A0 n_subdevices =3D (board->ai_n_chan ? 1 : 0) + board->has_ao + =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 board->has_dig_in += board->has_dig_out + =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 board->has_ttl_io; =C2=A0 =C2=A0 =C2=A0ret =3D comedi_alloc_subdevices(dev, n_subdevices);