mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 20:33:58 -04:00
ASoC: msm-pcm-q6-v2: Add dsp buf check
Current logic copies user buf size of data from the avail dsp buf at a given offset. If this offset returned from DSP in READ_DONE event goes out of bounds or is corrupted, then it can lead to out of bounds DSP buffer access, resulting in memory fault. Fix is to add check for this buf offset, if it is within the buf size range. Change-Id: I7753cc6db394704dbb959477150141d42b836bef Signed-off-by: Soumya Managoli <quic_c_smanag@quicinc.com>
This commit is contained in:
parent
7d196f8368
commit
02230ca65b
1 changed files with 9 additions and 1 deletions
|
|
@ -1,6 +1,6 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
/*
|
||||
* Add support for 24 and 32bit format for ASM loopback and playback session.
|
||||
|
|
@ -1328,6 +1328,14 @@ static int msm_pcm_capture_copy(struct snd_pcm_substream *substream,
|
|||
xfer = size;
|
||||
offset = prtd->in_frame_info[idx].offset;
|
||||
pr_debug("Offset value = %d\n", offset);
|
||||
|
||||
if (offset >= size) {
|
||||
pr_err("%s: Invalid dsp buf offset\n", __func__);
|
||||
ret = -EFAULT;
|
||||
q6asm_cpu_buf_release(OUT, prtd->audio_client);
|
||||
goto fail;
|
||||
}
|
||||
|
||||
if (size == 0 || size < prtd->pcm_count) {
|
||||
memset(bufptr + offset + size, 0, prtd->pcm_count - size);
|
||||
if (fbytes > prtd->pcm_count)
|
||||
|
|
|
|||
Loading…
Reference in a new issue