[PATCH] iio: pressure: bmp280: fix out-of-bounds access in sampling frequency lookup

From: Hui Su

Date: Wed Aug 05 2026 - 03:48:21 EST


The sampling frequency tables store each frequency as an integer part
and a fractional part in micro units. num_sampling_freq_avail is
initialized to the number of flattened integer elements because
read_avail() returns the table as a flat array.

bmp280_write_sampling_frequency(), however, indexes the same table as a
two-dimensional array and uses num_sampling_freq_avail as the number of
rows. This makes the lookup walk past the end of the table when an
unsupported sampling frequency is written.

Convert the flattened element count back to the number of rows before
iterating over the table.

Fixes: 10b40ffba2f9 ("iio: pressure: bmp280: Add more tunable config parameters for BMP380")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Hui Su <sh_def@xxxxxxx>
---
drivers/iio/pressure/bmp280-core.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/iio/pressure/bmp280-core.c b/drivers/iio/pressure/bmp280-core.c
index 990340a9b10c..ddd2de3c35ba 100644
--- a/drivers/iio/pressure/bmp280-core.c
+++ b/drivers/iio/pressure/bmp280-core.c
@@ -836,7 +836,8 @@ static int bmp280_write_sampling_frequency(struct bmp280_data *data,
int val, int val2)
{
const int (*avail)[2] = data->chip_info->sampling_freq_avail;
- const int n = data->chip_info->num_sampling_freq_avail;
+ const int n = data->chip_info->num_sampling_freq_avail /
+ ARRAY_SIZE(*avail);
int ret, prev;
int i;

--
2.43.0