mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
smcinvoke : file private data validation which is sent by userspace
a validation added to check whether retrieved struct smcinvoke_file_data inside the function get_server_id belongs to g_smcinvoke_fops or not. Change-Id: If949889a764775200650a8d0b744359c0611b576 Signed-off-by: Pavan Bobba <quic_pav@quicinc.com>
This commit is contained in:
parent
f094cbc663
commit
2fa26c84e7
1 changed files with 2 additions and 4 deletions
|
|
@ -617,15 +617,13 @@ static uint16_t get_server_id(int cb_server_fd)
|
|||
struct smcinvoke_file_data *svr_cxt = NULL;
|
||||
struct file *tmp_filp = fget(cb_server_fd);
|
||||
|
||||
if (!tmp_filp)
|
||||
if (!tmp_filp || !FILE_IS_REMOTE_OBJ(tmp_filp))
|
||||
return server_id;
|
||||
|
||||
svr_cxt = tmp_filp->private_data;
|
||||
if (svr_cxt && svr_cxt->context_type == SMCINVOKE_OBJ_TYPE_SERVER)
|
||||
server_id = svr_cxt->server_id;
|
||||
|
||||
if (tmp_filp)
|
||||
fput(tmp_filp);
|
||||
fput(tmp_filp);
|
||||
|
||||
return server_id;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue