forked from rubenslte/android_kernel_samsung_msm8226
ASoC: msm: initialize the params array before using it
The params array is used without initialization, which may cause security issues. Initialize it as all zero after the definition. CRs-Fixed: 1062271 Change-Id: If462fe3d82f139d72547f82dc7eb564f83cb35bf Signed-off-by: Walter Yang <yandongy@codeaurora.org>
This commit is contained in:
committed by
Gerrit - the friendly Code Review server
parent
af99b4f13a
commit
951440dc08
@@ -1031,6 +1031,7 @@ static int msm_compr_ioctl(struct snd_pcm_substream *substream,
|
||||
struct snd_dec_ddp *ddp =
|
||||
&compr->info.codec_param.codec.options.ddp;
|
||||
uint32_t params_length = 0;
|
||||
memset(params_value, 0, MAX_AC3_PARAM_SIZE);
|
||||
/* check integer overflow */
|
||||
if (ddp->params_length > UINT_MAX/sizeof(int)) {
|
||||
pr_err("%s: Integer overflow ddp->params_length %d\n",
|
||||
@@ -1075,6 +1076,7 @@ static int msm_compr_ioctl(struct snd_pcm_substream *substream,
|
||||
struct snd_dec_ddp *ddp =
|
||||
&compr->info.codec_param.codec.options.ddp;
|
||||
uint32_t params_length = 0;
|
||||
memset(params_value, 0, MAX_AC3_PARAM_SIZE);
|
||||
/* check integer overflow */
|
||||
if (ddp->params_length > UINT_MAX/sizeof(int)) {
|
||||
pr_err("%s: Integer overflow ddp->params_length %d\n",
|
||||
|
||||
Reference in New Issue
Block a user