msm: ipa: fix potential heap overflow in intf property queries.

Number of TX/RX/EXT properties to be read is supplied by
user-space and if these values are maliciously set too large,
heap overflow and memory corruption can result. This commit
caps the max allowed interface properties.

Change-Id: I9f5bf8b5e9a1b3b47b0741c0b00d5fafc77b28e2
Signed-off-by: Ravi Gummadidala <rgummadi@codeaurora.org>
Signed-off-by: Venkata Aravind <venkata@codeaurora.org>
This commit is contained in:
Venkata Aravind
2014-03-23 23:42:57 -07:00
committed by Gerrit - the friendly Code Review server
parent ae0f7ca684
commit 841868cf57
3 changed files with 31 additions and 0 deletions
+14
View File
@@ -544,6 +544,13 @@ static long ipa_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
retval = -EFAULT;
break;
}
if (((struct ipa_ioc_query_intf_tx_props *)header)->num_tx_props
> IPA_NUM_PROPS_MAX) {
retval = -EFAULT;
break;
}
pyld_sz = sz + ((struct ipa_ioc_query_intf_tx_props *)
header)->num_tx_props *
sizeof(struct ipa_ioc_tx_intf_prop);
@@ -572,6 +579,13 @@ static long ipa_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
retval = -EFAULT;
break;
}
if (((struct ipa_ioc_query_intf_rx_props *)header)->num_rx_props
> IPA_NUM_PROPS_MAX) {
retval = -EFAULT;
break;
}
pyld_sz = sz + ((struct ipa_ioc_query_intf_rx_props *)
header)->num_rx_props *
sizeof(struct ipa_ioc_rx_intf_prop);
+12
View File
@@ -60,6 +60,18 @@ int ipa_register_intf(const char *name, const struct ipa_tx_intf *tx,
return -EINVAL;
}
if (tx && tx->num_props > IPA_NUM_PROPS_MAX) {
IPAERR("invalid tx num_props=%d max=%d\n", tx->num_props,
IPA_NUM_PROPS_MAX);
return -EINVAL;
}
if (rx && rx->num_props > IPA_NUM_PROPS_MAX) {
IPAERR("invalid rx num_props=%d max=%d\n", rx->num_props,
IPA_NUM_PROPS_MAX);
return -EINVAL;
}
len = sizeof(struct ipa_intf);
intf = kzalloc(len, GFP_KERNEL);
if (intf == NULL) {
+5
View File
@@ -63,6 +63,11 @@
*/
#define IPA_RESOURCE_NAME_MAX 20
/**
* max number of interface properties
*/
#define IPA_NUM_PROPS_MAX 20
/**
* size of the mac address
*/