forked from rubenslte/android_kernel_samsung_msm8226
crypto: Fix possible stack out of bound error
Adding fix to check upper limit on the length of the destination array while copying elements from source address to avoid stack out of bound error. Change-Id: Ieb24e8f9b4a2b53fbc9442b25d790b12f737d471 Signed-off-by: Tanwee Kausar <tkausar@codeaurora.org> Issue: SEC-2931 (cherry picked from commit 4e921964bd0686950cd89eca69e77a5f3f109d3a)
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
2c6e06a790
commit
6a19ac3adc
@@ -1,6 +1,6 @@
|
||||
/* Qualcomm Crypto Engine driver.
|
||||
*
|
||||
* Copyright (c) 2010-2016, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2010-2016, 2020 The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -768,6 +768,11 @@ static int _ce_setup(struct qce_device *pce_dev, struct qce_req *q_req,
|
||||
switch (q_req->alg) {
|
||||
case CIPHER_ALG_DES:
|
||||
if (q_req->mode != QCE_MODE_ECB) {
|
||||
if (ivsize > MAX_IV_LENGTH) {
|
||||
pr_err("%s: error: Invalid length parameter\n",
|
||||
__func__);
|
||||
return -EINVAL;
|
||||
}
|
||||
_byte_stream_to_net_words(enciv32, q_req->iv, ivsize);
|
||||
writel_relaxed(enciv32[0], pce_dev->iobase +
|
||||
CRYPTO_CNTR0_IV0_REG);
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
/* Qualcomm Crypto Engine driver.
|
||||
*
|
||||
* Copyright (c) 2012-2014, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2012-2014, 2020 The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -788,6 +788,11 @@ static int _ce_setup_cipher(struct qce_device *pce_dev, struct qce_req *creq,
|
||||
switch (creq->alg) {
|
||||
case CIPHER_ALG_DES:
|
||||
if (creq->mode != QCE_MODE_ECB) {
|
||||
if (ivsize > MAX_IV_LENGTH) {
|
||||
pr_err("%s: error: Invalid length parameter\n",
|
||||
__func__);
|
||||
return -EINVAL;
|
||||
}
|
||||
_byte_stream_to_net_words(enciv32, creq->iv, ivsize);
|
||||
pce = cmdlistinfo->encr_cntr_iv;
|
||||
pce->data = enciv32[0];
|
||||
|
||||
Reference in New Issue
Block a user