forked from rubenslte/android_kernel_samsung_msm8226
dsp: avtimer: validate payload size before memory copy
Check payload size to avoid out-of-boundary memory access before attemptimg memory read. Change-Id: Id22f5c4e50c788053a0529e2d252e497991e1a38 Signed-off-by: Soumya Managoli <smanag@codeaurora.org> [haggertk: Backport to 3.4/msm8974. Path change.] CVE-2019-10626 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
matteo0026
parent
a16d6068bc
commit
29438f7684
@@ -1,4 +1,4 @@
|
||||
/* Copyright (c) 2012-2014, The Linux Foundation. All rights reserved.
|
||||
/* Copyright (c) 2012-2016, 2019, The Linux Foundation. All rights reserved.
|
||||
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -93,6 +93,13 @@ static int32_t aprv2_core_fn_q(struct apr_client_data *data, void *priv)
|
||||
}
|
||||
|
||||
payload1 = data->payload;
|
||||
|
||||
if (data->payload_size < 2 * sizeof(uint32_t)) {
|
||||
pr_err("%s: payload has invalid size %d\n",
|
||||
__func__, data->payload_size);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
switch (payload1[0]) {
|
||||
case AVCS_CMD_REMOTE_AVTIMER_RELEASE_REQUEST:
|
||||
pr_debug("%s: Cmd = TIMER RELEASE status[0x%x]\n",
|
||||
@@ -118,6 +125,11 @@ static int32_t aprv2_core_fn_q(struct apr_client_data *data, void *priv)
|
||||
}
|
||||
|
||||
case AVCS_CMD_RSP_REMOTE_AVTIMER_VOTE_REQUEST:
|
||||
if (data->payload_size < sizeof(uint32_t)) {
|
||||
pr_err("%s: payload has invalid size %d\n",
|
||||
__func__, data->payload_size);
|
||||
return -EINVAL;
|
||||
}
|
||||
payload1 = data->payload;
|
||||
pr_debug("%s: RSP_REMOTE_AVTIMER_VOTE_REQUEST handle %x\n",
|
||||
__func__, payload1[0]);
|
||||
|
||||
Reference in New Issue
Block a user