[PATCH v3] hwmon: (cros_ec) Avoid threshold temperature conversion overflows

From: Thomas Weißschuh

Date: Thu Jul 30 2026 - 11:41:54 EST


If the EC returns non-sensical values the temperature conversions might
overflow on 32-bit systems.

As these values wouldn't make sense, clamp them to 255 degrees celsius.
The machine would die before reaching that limit anyways.

Suggested-by: Guenter Roeck <linux@xxxxxxxxxxxx>
Link: https://lore.kernel.org/lkml/0fbf7f69-bb90-4209-b9d5-258759711496@xxxxxxxxxxxx/
Signed-off-by: Thomas Weißschuh <linux@xxxxxxxxxxxxxx>
---
Changes in v3:
- Drop the overflow handling and instead clamp the value sent by the EC
- Link to v2: https://patch.msgid.link/20260728-cros_ec-hwmon-overflow-v2-1-d24e24d0792b@xxxxxxxxxxxxxx

Changes in v2:
- Drop already applied patch 1.
- Also handle overflow of u32 -> long.
- Clarify commit message wrt compiler optimizations.
- Use __always_inline over __flatten to allow the compiler to optimize
away more unnecessary overflow checks.
- Link to v1: https://patch.msgid.link/20260630-cros_ec-hwmon-overflow-v1-0-3d2ecd3eb0f2@xxxxxxxxxxxxxx
---
drivers/hwmon/cros_ec_hwmon.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/hwmon/cros_ec_hwmon.c b/drivers/hwmon/cros_ec_hwmon.c
index 1337b646e022..27af13f0941c 100644
--- a/drivers/hwmon/cros_ec_hwmon.c
+++ b/drivers/hwmon/cros_ec_hwmon.c
@@ -236,8 +236,13 @@ static int cros_ec_hwmon_read(struct device *dev, enum hwmon_sensor_types type,
ret = cros_ec_hwmon_read_temp_threshold(priv->cros_ec, channel,
cros_ec_hwmon_attr_to_thres(attr),
&threshold);
- if (ret == 0)
- *val = cros_ec_hwmon_kelvin_to_millicelsius(threshold);
+ if (ret == 0) {
+ /* Limit to sensible, non-overflowing values. */
+ if (threshold > 255 + 273)
+ *val = 255000;
+ else
+ *val = cros_ec_hwmon_kelvin_to_millicelsius(threshold);
+ }
}
}


---
base-commit: 8a98254c65f629dcdc50a1046f58c5c87c72ef67
change-id: 20260630-cros_ec-hwmon-overflow-0381c8509df3

Best regards,
--
Thomas Weißschuh <linux@xxxxxxxxxxxxxx>