mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 14:19:09 -04:00
asoc: Add check to handle negative value passed for num_app_cfg_type
Long int negative value passed as part of ucontrol structure is assigned to int num_app_cfg_type making it positive and leading to overflow while populating maximum supported lsm_app_type_cfg structures. Change-Id: I81e3c75eea82265c8e8e1b3f8f95d9e334c895c4 Signed-off-by: Harshal Ahire <hahire@codeaurora.org>
This commit is contained in:
parent
111a7ea848
commit
33393c5a7e
1 changed files with 8 additions and 7 deletions
|
|
@ -1,5 +1,5 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/* Copyright (c) 2012-2020, The Linux Foundation. All rights reserved.
|
||||
/* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/init.h>
|
||||
|
|
@ -23262,9 +23262,9 @@ static int msm_routing_put_app_type_cfg_control(struct snd_kcontrol *kcontrol,
|
|||
|
||||
memset(app_type_cfg, 0, MAX_APP_TYPES*
|
||||
sizeof(struct msm_pcm_routing_app_type_data));
|
||||
if (num_app_types > MAX_APP_TYPES) {
|
||||
pr_err("%s: number of app types exceed the max supported\n",
|
||||
__func__);
|
||||
if (num_app_types > MAX_APP_TYPES || num_app_types < 0) {
|
||||
pr_err("%s: number of app types %d is invalid\n",
|
||||
__func__, num_app_types);
|
||||
return -EINVAL;
|
||||
}
|
||||
for (j = 0; j < num_app_types; j++) {
|
||||
|
|
@ -23468,9 +23468,10 @@ static int msm_routing_put_lsm_app_type_cfg_control(
|
|||
int i = 0, j;
|
||||
|
||||
mutex_lock(&routing_lock);
|
||||
if (ucontrol->value.integer.value[0] > MAX_APP_TYPES) {
|
||||
pr_err("%s: number of app types exceed the max supported\n",
|
||||
__func__);
|
||||
if (ucontrol->value.integer.value[0] < 0 ||
|
||||
ucontrol->value.integer.value[0] > MAX_APP_TYPES) {
|
||||
pr_err("%s: number of app types %ld is invalid\n",
|
||||
__func__, ucontrol->value.integer.value[0]);
|
||||
mutex_unlock(&routing_lock);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue