msm: eva: OOB write issue in fence processing

Added check for number of fences from user in kernel space before
fence processing.

Change-Id: I58f7899a811245a33357f19678557cb35b6a3736
Signed-off-by: Pulkit Singh Tak <ptak@qti.qualcomm.com>
This commit is contained in:
Pulkit Singh Tak 2025-12-30 11:39:53 +05:30
commit 1d2451ca45

View file

@ -741,6 +741,13 @@ static int msm_cvp_session_process_hfi_fence(struct msm_cvp_inst *inst,
f->output_index = kfc->output_index;
}
if (f->num_fences >= (MAX_HFI_FENCE_SIZE / 2)) {
dprintk(CVP_ERR, "%s: Max number of fences exceeded! Max number supported: %d",
__func__, (MAX_HFI_FENCE_SIZE / 2));
cvp_free_fence_data(f);
msm_cvp_unmap_frame(inst, pkt->client_data.kdata);
goto exit;
}
dprintk(CVP_SYNX, "%s: frameID %llu ktid %llu\n",
__func__, f->frame_id, pkt->client_data.kdata);