mirror of
https://github.com/LineageOS/android_kernel_samsung_msm8226.git
synced 2026-09-28 00:00:22 +02:00
Issue: When total_steps is updated, after that, copy_from_user fails with an error, then, i2c_reg_tbl is not allocated. In this case, when calling msm_actuator_parse_i2c_params, it lead to out-of-bound memory write. Fix: 1) Assign total_steps to zero when error from copying. 2) Add NULL pointer check for i2c tbl. CRs-Fixed: 2111672 Change-Id: Ib9dcb182356e2df8078c131edfd0791fa95a35e0 Signed-off-by: Haibin Liu <haibinl@codeaurora.org> [haggertk: Backport to 3.4/msm8974. Note that this includes patching the non-standard camera_ll implementation as well on this kernel.] CVE-2017-15857 Signed-off-by: Kevin F. Haggerty <haggertk@lineageos.org>