From 2ef6692192ffb7f3500fcdebc6263d90fb57b727 Mon Sep 17 00:00:00 2001 From: Jeya R Date: Tue, 18 May 2021 09:14:08 -0700 Subject: [PATCH] msm: adsprpc: Handle out-of-bounds read in debugfs Removed fixing the Title size which may not terminate the NULL character end of Title. And, this would fix the possible out-of-bounds read when reading debug-fs. Change-Id: Ib3ff2b0106a25232c7a766baaaaca5bd9d306533 Acked-by: Krishnaiah Tadakamalla Signed-off-by: Jeya R --- drivers/char/adsprpc.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c index ac55005bea79..051b43934810 100644 --- a/drivers/char/adsprpc.c +++ b/drivers/char/adsprpc.c @@ -64,7 +64,6 @@ #define FASTRPC_ENOSUCH 39 #define DEBUGFS_SIZE 3072 -#define UL_SIZE 25 #define PID_SIZE 10 #define AUDIO_PDR_ADSP_DTSI_PROPERTY_NAME "qcom,fastrpc-adsp-audio-pdr" @@ -5235,8 +5234,8 @@ static ssize_t fastrpc_debugfs_read(struct file *filp, char __user *buffer, unsigned int len = 0; int i, j, sess_used = 0, ret = 0; char *fileinfo = NULL; - char single_line[UL_SIZE] = "----------------"; - char title[UL_SIZE] = "========================="; + char single_line[] = "----------------"; + char title[] = "========================="; fileinfo = kzalloc(DEBUGFS_SIZE, GFP_KERNEL); if (!fileinfo) {