forked from rubenslte/android_kernel_samsung_msm8226
msm: ipa: fix potential heap overflow in intf property queries.
Number of TX/RX/EXT properties to be read is supplied by user-space and if these values are maliciously set too large, heap overflow and memory corruption can result. This commit caps the max allowed interface properties. Change-Id: I9f5bf8b5e9a1b3b47b0741c0b00d5fafc77b28e2 Signed-off-by: Ravi Gummadidala <rgummadi@codeaurora.org> Signed-off-by: Venkata Aravind <venkata@codeaurora.org>
This commit is contained in:
committed by
Gerrit - the friendly Code Review server
parent
ae0f7ca684
commit
841868cf57
@@ -544,6 +544,13 @@ static long ipa_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
|
||||
retval = -EFAULT;
|
||||
break;
|
||||
}
|
||||
|
||||
if (((struct ipa_ioc_query_intf_tx_props *)header)->num_tx_props
|
||||
> IPA_NUM_PROPS_MAX) {
|
||||
retval = -EFAULT;
|
||||
break;
|
||||
}
|
||||
|
||||
pyld_sz = sz + ((struct ipa_ioc_query_intf_tx_props *)
|
||||
header)->num_tx_props *
|
||||
sizeof(struct ipa_ioc_tx_intf_prop);
|
||||
@@ -572,6 +579,13 @@ static long ipa_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
|
||||
retval = -EFAULT;
|
||||
break;
|
||||
}
|
||||
|
||||
if (((struct ipa_ioc_query_intf_rx_props *)header)->num_rx_props
|
||||
> IPA_NUM_PROPS_MAX) {
|
||||
retval = -EFAULT;
|
||||
break;
|
||||
}
|
||||
|
||||
pyld_sz = sz + ((struct ipa_ioc_query_intf_rx_props *)
|
||||
header)->num_rx_props *
|
||||
sizeof(struct ipa_ioc_rx_intf_prop);
|
||||
|
||||
@@ -60,6 +60,18 @@ int ipa_register_intf(const char *name, const struct ipa_tx_intf *tx,
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (tx && tx->num_props > IPA_NUM_PROPS_MAX) {
|
||||
IPAERR("invalid tx num_props=%d max=%d\n", tx->num_props,
|
||||
IPA_NUM_PROPS_MAX);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (rx && rx->num_props > IPA_NUM_PROPS_MAX) {
|
||||
IPAERR("invalid rx num_props=%d max=%d\n", rx->num_props,
|
||||
IPA_NUM_PROPS_MAX);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
len = sizeof(struct ipa_intf);
|
||||
intf = kzalloc(len, GFP_KERNEL);
|
||||
if (intf == NULL) {
|
||||
|
||||
@@ -63,6 +63,11 @@
|
||||
*/
|
||||
#define IPA_RESOURCE_NAME_MAX 20
|
||||
|
||||
/**
|
||||
* max number of interface properties
|
||||
*/
|
||||
#define IPA_NUM_PROPS_MAX 20
|
||||
|
||||
/**
|
||||
* size of the mac address
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user