forked from rubenslte/android_kernel_samsung_msm8226
dsp: validate token before usage as array index
Token from DSP might be invalid for array index. Validate the token before being used as array index. Bug: 129850483 Change-Id: I9f47e1328d75d9f9acf7e85ddb452019b6eced0a Signed-off-by: Xiaojun Sang <xsang@codeaurora.org> Signed-off-by: Siqi Lin <siqilin@google.com> [haggertk: Backport to 3.4/msm8974] CVE-2019-2326 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
5a3ecd9fb6
commit
9c664cfcfe
@@ -1,4 +1,4 @@
|
||||
/* Copyright (c) 2012-2013, The Linux Foundation. All rights reserved.
|
||||
/* Copyright (c) 2012-2013, 2019 The Linux Foundation. All rights reserved.
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify
|
||||
* it under the terms of the GNU General Public License version 2 and
|
||||
@@ -102,6 +102,15 @@ void afe_set_aanc_info(struct aanc_data *q6_aanc_info)
|
||||
}
|
||||
|
||||
|
||||
static bool afe_token_is_valid(uint32_t token)
|
||||
{
|
||||
if (token >= AFE_MAX_PORTS) {
|
||||
pr_err("%s: token %d is invalid.\n", __func__, token);
|
||||
return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
static int32_t afe_callback(struct apr_client_data *data, void *priv)
|
||||
{
|
||||
int i;
|
||||
@@ -153,7 +162,10 @@ static int32_t afe_callback(struct apr_client_data *data, void *priv)
|
||||
#endif /* CONFIG_SND_SOC_MAXIM_DSM */
|
||||
} else
|
||||
atomic_set(&this_afe.state, -1);
|
||||
wake_up(&this_afe.wait[data->token]);
|
||||
if (afe_token_is_valid(data->token))
|
||||
wake_up(&this_afe.wait[data->token]);
|
||||
else
|
||||
return -EINVAL;
|
||||
} else if (data->payload_size) {
|
||||
uint32_t *payload;
|
||||
uint16_t port_id = 0;
|
||||
@@ -180,7 +192,10 @@ static int32_t afe_callback(struct apr_client_data *data, void *priv)
|
||||
case AFE_PORTS_CMD_DTMF_CTL:
|
||||
case AFE_SVC_CMD_SET_PARAM:
|
||||
atomic_set(&this_afe.state, 0);
|
||||
wake_up(&this_afe.wait[data->token]);
|
||||
if (afe_token_is_valid(data->token))
|
||||
wake_up(&this_afe.wait[data->token]);
|
||||
else
|
||||
return -EINVAL;
|
||||
break;
|
||||
case AFE_SERVICE_CMD_REGISTER_RT_PORT_DRIVER:
|
||||
break;
|
||||
@@ -208,7 +223,10 @@ static int32_t afe_callback(struct apr_client_data *data, void *priv)
|
||||
else
|
||||
this_afe.mmap_handle = (uint32_t)payload[0];
|
||||
atomic_set(&this_afe.state, 0);
|
||||
wake_up(&this_afe.wait[data->token]);
|
||||
if (afe_token_is_valid(data->token))
|
||||
wake_up(&this_afe.wait[data->token]);
|
||||
else
|
||||
return -EINVAL;
|
||||
} else if (data->opcode == AFE_EVENT_RT_PROXY_PORT_STATUS) {
|
||||
port_id = (uint16_t)(0x0000FFFF & payload[0]);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user