forked from rubenslte/android_kernel_samsung_msm8226
ASoC: msm: audio-effects: fix stack overread and heap overwrite
Fix overwrite of updt_params allocated in heap, and stack overread where param pointer is passed from user space. Bug: 27555224 Change-Id: Ida8bdb7da2fcb97023dce3b6eafe4b899a51cb66 Signed-off-by: Ravi Kumar Alamanda <arkumar@codeaurora.org> CVE-2016-2066 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
91078a612e
commit
3307c4ab46
File diff suppressed because it is too large
Load Diff
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (c) 2013, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2013-2016, The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -16,6 +16,8 @@
|
||||
|
||||
#include <sound/audio_effects.h>
|
||||
|
||||
#define MAX_PP_PARAMS_SZ 128
|
||||
|
||||
int msm_audio_effects_reverb_handler(struct audio_client *ac,
|
||||
struct reverb_params *reverb,
|
||||
long *values);
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
/* Copyright (c) 2012-2015, The Linux Foundation. All rights reserved.
|
||||
/* Copyright (c) 2012-2016, The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -1929,7 +1929,7 @@ static int msm_compr_audio_effects_config_info(struct snd_kcontrol *kcontrol,
|
||||
struct snd_ctl_elem_info *uinfo)
|
||||
{
|
||||
uinfo->type = SNDRV_CTL_ELEM_TYPE_INTEGER;
|
||||
uinfo->count = 128;
|
||||
uinfo->count = MAX_PP_PARAMS_SZ;
|
||||
uinfo->value.integer.min = 0;
|
||||
uinfo->value.integer.max = 0xFFFFFFFF;
|
||||
return 0;
|
||||
|
||||
Reference in New Issue
Block a user