commit | 0514e9acd7655c708fbf12a659ea43d835bc688a | [log] [tgz] |
---|---|---|
author | Axel Lin <axel.lin@gmail.com> | Mon May 16 22:19:01 2011 +0800 |
committer | Liam Girdwood <lrg@slimlogic.co.uk> | Fri May 27 10:49:09 2011 +0100 |
tree | 5f9ecf1224773a0ca671d8d516c507d133cbf2f1 | |
parent | 4aa922c024b2a194d7b68b22a66dfcf86e7838b3 [diff] |
mfd: Fix off-by-one value range checking for tps65910_i2c_write If bytes == (TPS65910_MAX_REGISTER + 1), we have a buffer overflow when doing memcpy(&msg[1], src, bytes). Signed-off-by: Axel Lin <axel.lin@gmail.com> Acked-by: Samuel Ortiz <sameo@linux.intel.com> Signed-off-by: Liam Girdwood <lrg@slimlogic.co.uk>