From d03322624e6c4ba4888e782347eb274de78b60bf Mon Sep 17 00:00:00 2001 From: Luca Toniolo <10792599+grandixximo@users.noreply.github.com> Date: Sun, 4 Oct 2026 21:10:36 +0800 Subject: [PATCH] hostmot2: fix bounds of the sserial global duplicate check The loop that tells process records apart from globals ran with i <= num_confs, reading one entry past the confs array, and dereferenced chan->confs even when the remote has no process records at all (confs == NULL), crashing the driver load on such a device. Bound the loop to num_confs, which also skips it safely for a globals-only remote. --- src/hal/drivers/mesa-hostmot2/sserial.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/hal/drivers/mesa-hostmot2/sserial.c b/src/hal/drivers/mesa-hostmot2/sserial.c index d0030a214f3..1954709a0b5 100644 --- a/src/hal/drivers/mesa-hostmot2/sserial.c +++ b/src/hal/drivers/mesa-hostmot2/sserial.c @@ -519,7 +519,7 @@ int hm2_sserial_get_globals_list(hostmot2_t *hm2, hm2_sserial_remote_t *chan){ return -EINVAL; } // process is a subset of global. The only way to tell is to compare - for (i = 0; i <= chan->num_confs ; i ++) { + for (i = 0; i < chan->num_confs ; i ++) { if (chan->confs[i].ParmAddr == data.ParmAddr){i = 1000;} } if (data.RecordType == LBP_DATA && i < 1000) {