forked from rubenslte/android_kernel_samsung_msm8226
msm: camera: cpp: Check for valid tx level
TX and RX FIFOs of Microcontroller are used to exchange commands and messages between Micro FW and CPP driver. TX FIFO depth is 16 32-bit words, incase of errors there is a chance of overflow. To prevent possible out of bound access, TX FIFO depth or level is checked for MAX depth before accessing the FIFO. Change-Id: I5adf39b46ff10e358c4a2c03a2de07d44b99cedb Signed-off-by: Pratap Nirujogi <pratapn@codeaurora.org> [haggertk: Backport to 3.4/msm8974. Note that this includes patching the non-standard camera_ll implementation as well on this kernel.] CVE-2018-11986 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
73d835385a
commit
25e839b89c
@@ -1,4 +1,4 @@
|
||||
/* Copyright (c) 2013, The Linux Foundation. All rights reserved.
|
||||
/* Copyright (c) 2013, 2018 The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -538,9 +538,14 @@ static irqreturn_t msm_cpp_irq(int irq_num, void *data)
|
||||
if (irq_status & 0x8) {
|
||||
tx_level = msm_camera_io_r(cpp_dev->base +
|
||||
MSM_CPP_MICRO_FIFO_TX_STAT) >> 2;
|
||||
for (i = 0; i < tx_level; i++) {
|
||||
tx_fifo[i] = msm_camera_io_r(cpp_dev->base +
|
||||
MSM_CPP_MICRO_FIFO_TX_DATA);
|
||||
if (tx_level < MSM_CPP_TX_FIFO_LEVEL) {
|
||||
for (i = 0; i < tx_level; i++) {
|
||||
tx_fifo[i] = msm_camera_io_r(cpp_dev->base +
|
||||
MSM_CPP_MICRO_FIFO_TX_DATA);
|
||||
}
|
||||
} else {
|
||||
pr_err("Fatal invalid tx level %d", tx_level);
|
||||
goto err;
|
||||
}
|
||||
spin_lock_irqsave(&cpp_dev->tasklet_lock, flags);
|
||||
queue_cmd = &cpp_dev->tasklet_queue_cmd[cpp_dev->taskletq_idx];
|
||||
@@ -594,6 +599,7 @@ static irqreturn_t msm_cpp_irq(int irq_num, void *data)
|
||||
pr_err("%s: DEBUG_R1: 0x%x\n", __func__,
|
||||
msm_camera_io_r(cpp_dev->cpp_hw_base + 0x8C));
|
||||
}
|
||||
err:
|
||||
msm_camera_io_w(irq_status, cpp_dev->base + MSM_CPP_MICRO_IRQGEN_CLR);
|
||||
return IRQ_HANDLED;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user