From 25e839b89c600fbafa23b123b5a06fe922d95778 Mon Sep 17 00:00:00 2001 From: Pratap Nirujogi Date: Wed, 8 Aug 2018 20:43:29 +0530 Subject: [PATCH] msm: camera: cpp: Check for valid tx level TX and RX FIFOs of Microcontroller are used to exchange commands and messages between Micro FW and CPP driver. TX FIFO depth is 16 32-bit words, incase of errors there is a chance of overflow. To prevent possible out of bound access, TX FIFO depth or level is checked for MAX depth before accessing the FIFO. Change-Id: I5adf39b46ff10e358c4a2c03a2de07d44b99cedb Signed-off-by: Pratap Nirujogi [haggertk: Backport to 3.4/msm8974. Note that this includes patching the non-standard camera_ll implementation as well on this kernel.] CVE-2018-11986 Signed-off-by: Kevin F. Haggerty --- .../platform/msm/camera_v2/pproc/cpp/msm_cpp.c | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c b/drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c index 01d0cd31f98..9807607ce86 100644 --- a/drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c +++ b/drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c @@ -1,4 +1,4 @@ -/* Copyright (c) 2013, The Linux Foundation. All rights reserved. +/* Copyright (c) 2013, 2018 The Linux Foundation. All rights reserved. * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License version 2 and @@ -538,9 +538,14 @@ static irqreturn_t msm_cpp_irq(int irq_num, void *data) if (irq_status & 0x8) { tx_level = msm_camera_io_r(cpp_dev->base + MSM_CPP_MICRO_FIFO_TX_STAT) >> 2; - for (i = 0; i < tx_level; i++) { - tx_fifo[i] = msm_camera_io_r(cpp_dev->base + - MSM_CPP_MICRO_FIFO_TX_DATA); + if (tx_level < MSM_CPP_TX_FIFO_LEVEL) { + for (i = 0; i < tx_level; i++) { + tx_fifo[i] = msm_camera_io_r(cpp_dev->base + + MSM_CPP_MICRO_FIFO_TX_DATA); + } + } else { + pr_err("Fatal invalid tx level %d", tx_level); + goto err; } spin_lock_irqsave(&cpp_dev->tasklet_lock, flags); queue_cmd = &cpp_dev->tasklet_queue_cmd[cpp_dev->taskletq_idx]; @@ -594,6 +599,7 @@ static irqreturn_t msm_cpp_irq(int irq_num, void *data) pr_err("%s: DEBUG_R1: 0x%x\n", __func__, msm_camera_io_r(cpp_dev->cpp_hw_base + 0x8C)); } +err: msm_camera_io_w(irq_status, cpp_dev->base + MSM_CPP_MICRO_IRQGEN_CLR); return IRQ_HANDLED; }