Re: [PATCH v2] iio: pressure: bmp280: fix out-of-bounds access in sampling frequency lookup
From: Jonathan Cameron
Date: Sat Aug 15 2026 - 17:58:46 EST
On Tue, 11 Aug 2026 10:52:53 +0800
Hui Su <sh_def@xxxxxxx> wrote:
> The sampling frequency tables store each frequency as an integer part and
> a fractional part in micro units. num_sampling_freq_avail is initialized
> to the number of flattened integer elements because read_avail() returns
> the table as a flat array.
>
> bmp280_write_sampling_frequency(), however, indexes the same table as a
> two-dimensional array and uses num_sampling_freq_avail as the number of
> rows. Convert the flattened element count back to the number of rows
> before iterating over the table.
>
> Fixes: 10b40ffba2f9 ("iio: pressure: bmp280: Add more tunable config parameters for BMP380")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Hui Su <sh_def@xxxxxxx>
> Reviewed-by: Joshua Crofts <joshua.crofts1@xxxxxxxxx>
Hi Hui Su
For future reference don't send a new version in reply to an older one. It rapidly looses
all usefulness as the email threads get deeper and more complex.
LGTM Applied to the fixes-togreg branch of iio.git
Note I plan to rebase that once rc1 is out and a pull request will go upstream
sometime after that.
Thanks,
Jonathan
> ---
> Changes in v2:
> - Use plain 2 as the divisor, as suggested by Andy Shevchenko.
> - Add Joshua Crofts' Reviewed-by tag.
> Link: https://lore.kernel.org/lkml/20260805074127.473731-1-sh_def@xxxxxxx/
>
> drivers/iio/pressure/bmp280-core.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/iio/pressure/bmp280-core.c b/drivers/iio/pressure/bmp280-core.c
> index 990340a9b10c..dbe42233c81d 100644
> --- a/drivers/iio/pressure/bmp280-core.c
> +++ b/drivers/iio/pressure/bmp280-core.c
> @@ -836,7 +836,7 @@ static int bmp280_write_sampling_frequency(struct bmp280_data *data,
> int val, int val2)
> {
> const int (*avail)[2] = data->chip_info->sampling_freq_avail;
> - const int n = data->chip_info->num_sampling_freq_avail;
> + const int n = data->chip_info->num_sampling_freq_avail / 2;
> int ret, prev;
> int i;
>