Skip to content

Commit 7440fcd

Browse files
committed
char: tpm: tpm-buf: Add sanity check fallback in read helpers
JIRA: https://issues.redhat.com/browse/RHEL-72765 Upstream Status: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git commit 32d495b Author: Purva Yeshi <purvayeshi550@gmail.com> Date: Thu Apr 10 16:04:42 2025 +0530 char: tpm: tpm-buf: Add sanity check fallback in read helpers Fix Smatch-detected issue: drivers/char/tpm/tpm-buf.c:208 tpm_buf_read_u8() error: uninitialized symbol 'value'. drivers/char/tpm/tpm-buf.c:225 tpm_buf_read_u16() error: uninitialized symbol 'value'. drivers/char/tpm/tpm-buf.c:242 tpm_buf_read_u32() error: uninitialized symbol 'value'. Zero-initialize the return values in tpm_buf_read_u8(), tpm_buf_read_u16(), and tpm_buf_read_u32() to guard against uninitialized data in case of a boundary overflow. Add defensive initialization ensures the return values are always defined, preventing undefined behavior if the unexpected happens. Signed-off-by: Purva Yeshi <purvayeshi550@gmail.com> Reviewed-by: Stefano Garzarella <sgarzare@redhat.com> Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Jarkko Sakkinen <jarkko@kernel.org> Signed-off-by: Štěpán Horáček <shoracek@redhat.com>
1 parent fff9296 commit 7440fcd

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

drivers/char/tpm/tpm-buf.c

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -180,7 +180,7 @@ static void tpm_buf_read(struct tpm_buf *buf, off_t *offset, size_t count, void
180180
*/
181181
u8 tpm_buf_read_u8(struct tpm_buf *buf, off_t *offset)
182182
{
183-
u8 value;
183+
u8 value = 0;
184184

185185
tpm_buf_read(buf, offset, sizeof(value), &value);
186186

@@ -197,7 +197,7 @@ EXPORT_SYMBOL_GPL(tpm_buf_read_u8);
197197
*/
198198
u16 tpm_buf_read_u16(struct tpm_buf *buf, off_t *offset)
199199
{
200-
u16 value;
200+
u16 value = 0;
201201

202202
tpm_buf_read(buf, offset, sizeof(value), &value);
203203

@@ -214,7 +214,7 @@ EXPORT_SYMBOL_GPL(tpm_buf_read_u16);
214214
*/
215215
u32 tpm_buf_read_u32(struct tpm_buf *buf, off_t *offset)
216216
{
217-
u32 value;
217+
u32 value = 0;
218218

219219
tpm_buf_read(buf, offset, sizeof(value), &value);
220220

0 commit comments

Comments
 (0)