forked from rubenslte/android_kernel_samsung_msm8226
Both damn things interpret userland pointers embedded into the payload; worse, they are actually traversing those. Leaving aside the bad API design, this is very much _not_ safe to call with KERNEL_DS. Bail out early if that happens. Change-Id: I3b5b01ea1c13326d873faa17b2edcadf4c77eb94 Cc: stable@vger.kernel.org Signed-off-by: Al Viro <viro@zeniv.linux.org.uk> CVE-2016-10088 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>