dsi_panel: fix out-of-bounds issue

PROPAGATED_from (CR)

Before make the read operation, malloc the space of rx_buf.
To avoid the out-of-bounds  issue.

Change-Id: If5debbae4957845bf6bd35f9f81eaca79faa54e5
Reviewed-on: https://gerrit.mot.com/1782951
SLTApproved: Slta Waiver
SME-Granted: SME Approvals Granted
Tested-by: Jira Key
Reviewed-by: Yeqing Wang <wangyq13@motorola.com>
Reviewed-by: Shanshan Dai <daiss1@motorola.com>
Reviewed-by: Huosheng Liao <liaohs@motorola.com>
Submit-Approved: Jira Key
This commit is contained in:
houdz1 2020-05-26 16:14:15 +08:00 • committed by tongkun1
commit 26fc3c214a

View file

@ -4054,6 +4054,7 @@ static int dsi_panel_get_pwr_mode(struct dsi_panel *panel, u8 *val)
struct dsi_display *display = NULL;
u32 flags;
u8 payload = MIPI_DCS_GET_POWER_MODE;
u32 rx_buf;
display = container_of(panel->host, struct dsi_display, host);
if (!display) {
@ -4073,7 +4074,7 @@ static int dsi_panel_get_pwr_mode(struct dsi_panel *panel, u8 *val)
cmd.msg.tx_len = 1;
cmd.msg.tx_buf = &payload;
cmd.msg.rx_len = 1;
cmd.msg.rx_buf = val;
cmd.msg.rx_buf = &rx_buf;
rc = dsi_display_cmd_mipi_transfer(display, &cmd.msg, flags);
if (rc <= 0) {
@ -4081,6 +4082,8 @@ static int dsi_panel_get_pwr_mode(struct dsi_panel *panel, u8 *val)
rc = -EIO;
} else
rc = 0;
*val = rx_buf & 0xFF;
end:
return rc;