rpmsg: slatecom: out of bound read from process_cmd

When dereferencing "rx_data" as type "glink_slatecom_msg" ,
we didn't check if "rx_data" has enough room to hold that type.
The "rx_size" is read from slate to master fifo and if received
rx_size is less then "glink_slatecom_msg" then it could lead to
heap out of bounds read.

If received rx_size is less then the expected glink_slatecom_msg
then return back as a bad message.

Change-Id: Idde757ee70c7c88c22e4f036e6da0280e3b385d0
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit 7ddb61a6ac)
This commit is contained in:
Kaushal Hooda 2023-06-02 20:21:06 +05:30 • committed by Surapusetty Naresh Babu
commit 0106549bb9

View file

@ -1900,7 +1900,7 @@ static void glink_slatecom_handle_rx_done(struct glink_slatecom *glink,
mutex_unlock(&channel->intent_lock);
}
static void glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_data,
static int glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_data,
u32 rx_size)
{
struct glink_slatecom_msg *msg;
@ -1909,12 +1909,18 @@ static void glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_da
unsigned int param3;
unsigned int param4;
unsigned int cmd;
int offset = 0;
int ret;
u32 offset = 0;
int ret = 0;
u16 name_len;
char *name;
while (offset < rx_size) {
if (rx_size - offset < sizeof(struct glink_slatecom_msg)) {
ret = -EBADMSG;
GLINK_ERR(glink, "%s: Error %d process cmd\n", __func__, ret);
return ret;
}
msg = (struct glink_slatecom_msg *)(rx_data + offset);
offset += sizeof(*msg);
@ -1997,6 +2003,7 @@ static void glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_da
break;
}
}
return ret;
}
/**