mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 04:12:04 -04:00
rpmsg: slatecom: out of bound read from process_cmd
When dereferencing "rx_data" as type "glink_slatecom_msg" ,
we didn't check if "rx_data" has enough room to hold that type.
The "rx_size" is read from slate to master fifo and if received
rx_size is less then "glink_slatecom_msg" then it could lead to
heap out of bounds read.
If received rx_size is less then the expected glink_slatecom_msg
then return back as a bad message.
Change-Id: Idde757ee70c7c88c22e4f036e6da0280e3b385d0
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit 7ddb61a6ac)
This commit is contained in:
parent
fad511703f
commit
0106549bb9
1 changed files with 10 additions and 3 deletions
|
|
@ -1900,7 +1900,7 @@ static void glink_slatecom_handle_rx_done(struct glink_slatecom *glink,
|
|||
mutex_unlock(&channel->intent_lock);
|
||||
}
|
||||
|
||||
static void glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_data,
|
||||
static int glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_data,
|
||||
u32 rx_size)
|
||||
{
|
||||
struct glink_slatecom_msg *msg;
|
||||
|
|
@ -1909,12 +1909,18 @@ static void glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_da
|
|||
unsigned int param3;
|
||||
unsigned int param4;
|
||||
unsigned int cmd;
|
||||
int offset = 0;
|
||||
int ret;
|
||||
u32 offset = 0;
|
||||
int ret = 0;
|
||||
u16 name_len;
|
||||
char *name;
|
||||
|
||||
while (offset < rx_size) {
|
||||
if (rx_size - offset < sizeof(struct glink_slatecom_msg)) {
|
||||
ret = -EBADMSG;
|
||||
GLINK_ERR(glink, "%s: Error %d process cmd\n", __func__, ret);
|
||||
return ret;
|
||||
}
|
||||
|
||||
msg = (struct glink_slatecom_msg *)(rx_data + offset);
|
||||
offset += sizeof(*msg);
|
||||
|
||||
|
|
@ -1997,6 +2003,7 @@ static void glink_slatecom_process_cmd(struct glink_slatecom *glink, void *rx_da
|
|||
break;
|
||||
}
|
||||
}
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
|
|
|
|||
Loading…
Reference in a new issue