From 1c8aec0cfd1fb3ffebd079e120700cfe68f0b743 Mon Sep 17 00:00:00 2001 From: Vatsal Bucha Date: Mon, 28 Jan 2019 18:54:56 +0530 Subject: [PATCH] dsp: q6usm: Check size of payload before access Check size of payload before access in q6usm_mmapcallback. Change-Id: Iff0672532c2ea40e7129237a92d8365d6b554cf2 Signed-off-by: Vatsal Bucha --- dsp/q6usm.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/dsp/q6usm.c b/dsp/q6usm.c index ce25c71e137f..287d63c1ab8c 100644 --- a/dsp/q6usm.c +++ b/dsp/q6usm.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2012-2018, The Linux Foundation. All rights reserved. + * Copyright (c) 2012-2019, The Linux Foundation. All rights reserved. */ #include #include @@ -490,6 +490,11 @@ static int32_t q6usm_mmapcallback(struct apr_client_data *data, void *priv) uint32_t token; uint32_t *payload = data->payload; + if (data->payload_size < (2 * sizeof(uint32_t))) { + pr_err("%s: payload has invalid size[%d]\n", __func__, + data->payload_size); + return -EINVAL; + } pr_debug("%s: ptr0[0x%x]; ptr1[0x%x]; opcode[0x%x]\n", __func__, payload[0], payload[1], data->opcode); pr_debug("%s: token[0x%x]; payload_size[%d]; src[%d]; dest[%d];\n",