forked from rubenslte/android_kernel_samsung_msm8226
ALSA: timer: Fix leak in events via snd_timer_user_tinterrupt
The stack object “r1” has a total size of 32 bytes. Its field “event” and “val” both contain 4 bytes padding. These 8 bytes padding bytes are sent to user without being initialized. b/28980217 Git-commit: e4ec8cc8039a7063e24204299b462bd1383184a5 Git-repo: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git Signed-off-by: Kangjie Lu <kjlu@gatech.edu> Signed-off-by: Takashi Iwai <tiwai@suse.de> Signed-off-by: Dennis Cagle <d-cagle@codeaurora.org> (cherry picked from commit e4ec8cc8039a7063e24204299b462bd1383184a5) Change-Id: I53aa15632e941199010aae670cefb65c8fd56833
This commit is contained in:
committed by
Gerrit - the friendly Code Review server
parent
52706bb60e
commit
1e9325f5e5
@@ -1219,6 +1219,7 @@ static void snd_timer_user_tinterrupt(struct snd_timer_instance *timeri,
|
||||
}
|
||||
if ((tu->filter & (1 << SNDRV_TIMER_EVENT_RESOLUTION)) &&
|
||||
tu->last_resolution != resolution) {
|
||||
memset(&r1, 0, sizeof(r1));
|
||||
r1.event = SNDRV_TIMER_EVENT_RESOLUTION;
|
||||
r1.tstamp = tstamp;
|
||||
r1.val = resolution;
|
||||
|
||||
Reference in New Issue
Block a user