hw/gpio/pca9552: fix off-by-one in QOM led index validation
pca955x_get_led() and pca955x_set_led() accept led indices equal to pin_count, but valid indices are 0..pin_count-1. For a 16-pin device, led16 passes the current check and then accesses an LS register past max_reg. Use the same >= pin_count bounds check as pca9554_set_pin() and the gpio input handler assert in this file. Fixes: a90d8f84674 ("misc/pca9552: Add qom set and get") Signed-off-by: yujun <yujun@kylinos.cn> Reviewed-by: Peter Maydell <peter.maydell@linaro.org> Reviewed-by: Glenn Miles <milesg@linux.ibm.com> Message-ID: <20260629074133.187549-1-yujun@kylinos.cn> Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
yujun committed
Jun 29, 2026 at 15:41 UTC
59b748ac6a130b34b459ad7e4ff50db6a121e0bc
1 file changed
+4
-4
hw/gpio/pca9552.c
+4
-4
@@ -311,8 +311,8 @@ static void pca955x_get_led(Object *obj, Visitor *v, const char *name,
311
error_setg(errp, "%s: error reading %s", __func__, name);
312
return;
313
}
314
- if (led < 0 || led > k->pin_count) {
315
- error_setg(errp, "%s invalid led %s", __func__, name);
314
+ if (led < 0 || led >= k->pin_count) {
315
+ error_setg(errp, "%s: invalid led %s", __func__, name);
316
return;
317
}
318
/*
@@ -352,8 +352,8 @@ static void pca955x_set_led(Object *obj, Visitor *v, const char *name,
352
error_setg(errp, "%s: error reading %s", __func__, name);
353
return;
354
}
355
- if (led < 0 || led > k->pin_count) {
356
- error_setg(errp, "%s invalid led %s", __func__, name);
355
+ if (led < 0 || led >= k->pin_count) {
356
+ error_setg(errp, "%s: invalid led %s", __func__, name);
357
return;
358
}
359