forked from rubenslte/android_kernel_samsung_msm8226
ASoC: msm: qdsp6v2: Set freed pointers to NULL
Set freed pointers to NULL to avoid double free in msm_compr_playback_open and msm_compr_playback_free functions of the compress driver. CRs-Fixed: 2142216 Bug: 68664502 Change-Id: Ifd011dd85dd9f610c7b69dd460f73d26e006cd66 Signed-off-by: Aditya Bavanari <abavanar@codeaurora.org> [haggertk: Backport to 3.4/msm8974] CVE-2018-3560 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>
This commit is contained in:
committed by
Francescodario Cuzzocrea
parent
6ca681311f
commit
f76eda3042
@@ -698,11 +698,16 @@ static int msm_compr_open(struct snd_compr_stream *cstream)
|
||||
{
|
||||
struct snd_compr_runtime *runtime = cstream->runtime;
|
||||
struct snd_soc_pcm_runtime *rtd = cstream->private_data;
|
||||
struct msm_compr_audio *prtd;
|
||||
struct msm_compr_audio *prtd = NULL;
|
||||
struct msm_compr_pdata *pdata =
|
||||
snd_soc_platform_get_drvdata(rtd->platform);
|
||||
|
||||
pr_debug("%s\n", __func__);
|
||||
if (pdata->is_in_use[rtd->dai_link->be_id] == true) {
|
||||
pr_err("%s: %s is already in use,err: %d ",
|
||||
__func__, rtd->dai_link->cpu_dai_name, -EBUSY);
|
||||
return -EBUSY;
|
||||
}
|
||||
prtd = kzalloc(sizeof(struct msm_compr_audio), GFP_KERNEL);
|
||||
if (prtd == NULL) {
|
||||
pr_err("Failed to allocate memory for msm_compr_audio\n");
|
||||
@@ -713,7 +718,7 @@ static int msm_compr_open(struct snd_compr_stream *cstream)
|
||||
pdata->cstream[rtd->dai_link->be_id] = cstream;
|
||||
pdata->audio_effects[rtd->dai_link->be_id] =
|
||||
kzalloc(sizeof(struct msm_compr_audio_effects), GFP_KERNEL);
|
||||
if (!pdata->audio_effects[rtd->dai_link->be_id]) {
|
||||
if (pdata->audio_effects[rtd->dai_link->be_id] == NULL) {
|
||||
pr_err("%s: Could not allocate memory for effects\n", __func__);
|
||||
pdata->cstream[rtd->dai_link->be_id] = NULL;
|
||||
kfree(prtd);
|
||||
@@ -721,10 +726,11 @@ static int msm_compr_open(struct snd_compr_stream *cstream)
|
||||
}
|
||||
pdata->dec_params[rtd->dai_link->be_id] =
|
||||
kzalloc(sizeof(struct msm_compr_dec_params), GFP_KERNEL);
|
||||
if (!pdata->dec_params[rtd->dai_link->be_id]) {
|
||||
if (pdata->dec_params[rtd->dai_link->be_id] == NULL) {
|
||||
pr_err("%s: Could not allocate memory for dec params\n",
|
||||
__func__);
|
||||
kfree(pdata->audio_effects[rtd->dai_link->be_id]);
|
||||
pdata->audio_effects[rtd->dai_link->be_id] = NULL;
|
||||
pdata->cstream[rtd->dai_link->be_id] = NULL;
|
||||
kfree(prtd);
|
||||
return -ENOMEM;
|
||||
@@ -734,7 +740,9 @@ static int msm_compr_open(struct snd_compr_stream *cstream)
|
||||
if (!prtd->audio_client) {
|
||||
pr_err("%s: Could not allocate memory for client\n", __func__);
|
||||
kfree(pdata->audio_effects[rtd->dai_link->be_id]);
|
||||
pdata->audio_effects[rtd->dai_link->be_id] = NULL;
|
||||
kfree(pdata->dec_params[rtd->dai_link->be_id]);
|
||||
pdata->dec_params[rtd->dai_link->be_id] = NULL;
|
||||
pdata->cstream[rtd->dai_link->be_id] = NULL;
|
||||
kfree(prtd);
|
||||
return -ENOMEM;
|
||||
@@ -793,7 +801,7 @@ static int msm_compr_open(struct snd_compr_stream *cstream)
|
||||
} else {
|
||||
pr_err("%s: Unsupported stream type", __func__);
|
||||
}
|
||||
|
||||
pdata->is_in_use[rtd->dai_link->be_id] = true;
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -865,9 +873,15 @@ static int msm_compr_free(struct snd_compr_stream *cstream)
|
||||
q6asm_audio_client_buf_free_contiguous(dir, ac);
|
||||
|
||||
q6asm_audio_client_free(ac);
|
||||
|
||||
kfree(pdata->audio_effects[soc_prtd->dai_link->be_id]);
|
||||
kfree(pdata->dec_params[soc_prtd->dai_link->be_id]);
|
||||
if (pdata->audio_effects[soc_prtd->dai_link->be_id] != NULL) {
|
||||
kfree(pdata->audio_effects[soc_prtd->dai_link->be_id]);
|
||||
pdata->audio_effects[soc_prtd->dai_link->be_id] = NULL;
|
||||
}
|
||||
if (pdata->dec_params[soc_prtd->dai_link->be_id] != NULL) {
|
||||
kfree(pdata->dec_params[soc_prtd->dai_link->be_id]);
|
||||
pdata->dec_params[soc_prtd->dai_link->be_id] = NULL;
|
||||
}
|
||||
pdata->is_in_use[soc_prtd->dai_link->be_id] = false;
|
||||
kfree(prtd);
|
||||
runtime->private_data = NULL;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user