dsp: validate token before usage as array index

Token from DSP might be invalid for array index. Validate the
token before being used as array index.

Bug: 129850483
Change-Id: I9f47e1328d75d9f9acf7e85ddb452019b6eced0a
Signed-off-by: Xiaojun Sang <xsang@codeaurora.org>
Signed-off-by: Siqi Lin <siqilin@google.com>
[haggertk: Backport to 3.4/msm8974]
CVE-2019-2326
Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
Xiaojun Sang
2019-08-09 12:05:47 +02:00
committed by Francescodario Cuzzocrea
parent 5a3ecd9fb6
commit 9c664cfcfe
+22 -4
View File
@@ -1,4 +1,4 @@
/* Copyright (c) 2012-2013, The Linux Foundation. All rights reserved.
/* Copyright (c) 2012-2013, 2019 The Linux Foundation. All rights reserved.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License version 2 and
@@ -102,6 +102,15 @@ void afe_set_aanc_info(struct aanc_data *q6_aanc_info)
}
static bool afe_token_is_valid(uint32_t token)
{
if (token >= AFE_MAX_PORTS) {
pr_err("%s: token %d is invalid.\n", __func__, token);
return false;
}
return true;
}
static int32_t afe_callback(struct apr_client_data *data, void *priv)
{
int i;
@@ -153,7 +162,10 @@ static int32_t afe_callback(struct apr_client_data *data, void *priv)
#endif /* CONFIG_SND_SOC_MAXIM_DSM */
} else
atomic_set(&this_afe.state, -1);
wake_up(&this_afe.wait[data->token]);
if (afe_token_is_valid(data->token))
wake_up(&this_afe.wait[data->token]);
else
return -EINVAL;
} else if (data->payload_size) {
uint32_t *payload;
uint16_t port_id = 0;
@@ -180,7 +192,10 @@ static int32_t afe_callback(struct apr_client_data *data, void *priv)
case AFE_PORTS_CMD_DTMF_CTL:
case AFE_SVC_CMD_SET_PARAM:
atomic_set(&this_afe.state, 0);
wake_up(&this_afe.wait[data->token]);
if (afe_token_is_valid(data->token))
wake_up(&this_afe.wait[data->token]);
else
return -EINVAL;
break;
case AFE_SERVICE_CMD_REGISTER_RT_PORT_DRIVER:
break;
@@ -208,7 +223,10 @@ static int32_t afe_callback(struct apr_client_data *data, void *priv)
else
this_afe.mmap_handle = (uint32_t)payload[0];
atomic_set(&this_afe.state, 0);
wake_up(&this_afe.wait[data->token]);
if (afe_token_is_valid(data->token))
wake_up(&this_afe.wait[data->token]);
else
return -EINVAL;
} else if (data->opcode == AFE_EVENT_RT_PROXY_PORT_STATUS) {
port_id = (uint16_t)(0x0000FFFF & payload[0]);
}