forked from rubenslte/android_kernel_samsung_msm8226
input: synaptics_fw_update: fix insufficient bounds checking
Possible values of config_area are between 0 and 3. The patch adds bounds checking in fwu_sysfs_config_area_store() function. Also use kstrtou16() for parsing the config_area. Change-Id: Ia0b58f1b5a359c67f420012876431dac920ecfbd Signed-off-by: Abinaya P <abinayap@codeaurora.org>
This commit is contained in:
@@ -1905,12 +1905,20 @@ static ssize_t fwu_sysfs_config_area_store(struct device *dev,
|
||||
struct device_attribute *attr, const char *buf, size_t count)
|
||||
{
|
||||
int retval;
|
||||
unsigned long config_area;
|
||||
unsigned short config_area;
|
||||
struct synaptics_rmi4_data *rmi4_data = fwu->rmi4_data;
|
||||
|
||||
retval = kstrtoul(buf, 10, &config_area);
|
||||
retval = kstrtou16(buf, 10, &config_area);
|
||||
if (retval)
|
||||
return retval;
|
||||
|
||||
if (config_area < 0x00 || config_area > 0x03) {
|
||||
dev_err(&rmi4_data->i2c_client->dev,
|
||||
"%s: Incorrect value of config_area\n",
|
||||
__func__);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
fwu->config_area = config_area;
|
||||
|
||||
return count;
|
||||
|
||||
Reference in New Issue
Block a user