forked from rubenslte/android_kernel_samsung_msm8226
dsp: asm: Add check for num_channels before calling q6asm_map_channels
Channel_mapping array size varies for different commands. Add check for num_channels before calling q6asm_map_channels. Bug: 129851238 Change-Id: Iccbcfe82f716fc0ffe0a26b1779dcaa1c3cb805b Signed-off-by: Rohit kumar <rohitkr@codeaurora.org> [haggertk: Backport to 3.4/msm8974] CVE-2019-2328 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
9c664cfcfe
commit
515cfaf1d3
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (c) 2012-2016, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2012-2016, 2019 The Linux Foundation. All rights reserved.
|
||||
* Author: Brian Swetland <swetland@google.com>
|
||||
*
|
||||
* This software is licensed under the terms of the GNU General Public
|
||||
@@ -2276,6 +2276,13 @@ int q6asm_set_encdec_chan_map(struct audio_client *ac,
|
||||
int rc = 0;
|
||||
pr_debug("%s: Session %d, num_channels = %d\n",
|
||||
__func__, ac->session, num_channels);
|
||||
|
||||
if (num_channels > MAX_CHAN_MAP_CHANNELS) {
|
||||
pr_err("%s: Invalid channel count %d\n", __func__,
|
||||
num_channels);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
q6asm_add_hdr(ac, &chan_map.hdr, sizeof(chan_map), TRUE);
|
||||
atomic_set(&ac->cmd_state, 1);
|
||||
chan_map.hdr.opcode = ASM_STREAM_CMD_SET_ENCDEC_PARAM;
|
||||
@@ -2318,6 +2325,11 @@ static int __q6asm_enc_cfg_blk_pcm(struct audio_client *ac,
|
||||
|
||||
int rc = 0;
|
||||
|
||||
if (channels > PCM_FORMAT_MAX_NUM_CHANNEL) {
|
||||
pr_err("%s: Invalid channel count %d\n", __func__, channels);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
pr_debug("%s: Session %d, rate = %d, channels = %d\n", __func__,
|
||||
ac->session, rate, channels);
|
||||
|
||||
@@ -2380,6 +2392,11 @@ int q6asm_enc_cfg_blk_pcm_native(struct audio_client *ac,
|
||||
|
||||
int rc = 0;
|
||||
|
||||
if (channels > PCM_FORMAT_MAX_NUM_CHANNEL) {
|
||||
pr_err("%s: Invalid channel count %d\n", __func__, channels);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
pr_debug("%s: Session %d, rate = %d, channels = %d\n", __func__,
|
||||
ac->session, rate, channels);
|
||||
|
||||
@@ -2759,6 +2776,11 @@ static int __q6asm_media_format_block_pcm(struct audio_client *ac,
|
||||
u8 *channel_mapping;
|
||||
int rc = 0;
|
||||
|
||||
if (channels > PCM_FORMAT_MAX_NUM_CHANNEL) {
|
||||
pr_err("%s: Invalid channel count %d\n", __func__, channels);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
pr_debug("%s:session[%d]rate[%d]ch[%d]\n", __func__, ac->session, rate,
|
||||
channels);
|
||||
|
||||
@@ -2820,6 +2842,11 @@ static int __q6asm_media_format_block_multi_ch_pcm(struct audio_client *ac,
|
||||
u8 *channel_mapping;
|
||||
int rc = 0;
|
||||
|
||||
if (channels > PCM_FORMAT_MAX_NUM_CHANNEL) {
|
||||
pr_err("%s: Invalid channel count %d\n", __func__, channels);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
pr_debug("%s:session[%d]rate[%d]ch[%d]\n", __func__, ac->session, rate,
|
||||
channels);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user