From 2fa26c84e7a4f96b409dc9fbbb2d03bc0e9faeb1 Mon Sep 17 00:00:00 2001 From: Pavan Bobba Date: Thu, 7 Apr 2022 18:28:46 +0530 Subject: [PATCH] smcinvoke : file private data validation which is sent by userspace a validation added to check whether retrieved struct smcinvoke_file_data inside the function get_server_id belongs to g_smcinvoke_fops or not. Change-Id: If949889a764775200650a8d0b744359c0611b576 Signed-off-by: Pavan Bobba --- drivers/soc/qcom/smcinvoke.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/drivers/soc/qcom/smcinvoke.c b/drivers/soc/qcom/smcinvoke.c index fcd929143a39..73f17e15da9f 100644 --- a/drivers/soc/qcom/smcinvoke.c +++ b/drivers/soc/qcom/smcinvoke.c @@ -617,15 +617,13 @@ static uint16_t get_server_id(int cb_server_fd) struct smcinvoke_file_data *svr_cxt = NULL; struct file *tmp_filp = fget(cb_server_fd); - if (!tmp_filp) + if (!tmp_filp || !FILE_IS_REMOTE_OBJ(tmp_filp)) return server_id; svr_cxt = tmp_filp->private_data; if (svr_cxt && svr_cxt->context_type == SMCINVOKE_OBJ_TYPE_SERVER) server_id = svr_cxt->server_id; - - if (tmp_filp) - fput(tmp_filp); + fput(tmp_filp); return server_id; }