mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 22:40:54 -04:00
qcedev: check num_fds during unmap
check the num_fds passed into unmap buf ioctl, or else it can lead to an out of bounds access. Test: Build compilation. qcedev tests. Change-Id: I206ba01dfa989346ade769a0f68b372b21f84043 Signed-off-by: Gaurav Kashyap <quic_gaurkash@quicinc.com> Signed-off-by: Pranav Lavhate <quic_plavhate@quicinc.com>
This commit is contained in:
parent
29d7ace1da
commit
3ae07bc558
1 changed files with 9 additions and 1 deletions
|
|
@ -1916,7 +1916,9 @@ long qcedev_ioctl(struct file *file,
|
|||
goto exit_free_qcedev_areq;
|
||||
}
|
||||
|
||||
if (map_buf.num_fds > QCEDEV_MAX_BUFFERS) {
|
||||
if (map_buf.num_fds > ARRAY_SIZE(map_buf.fd)) {
|
||||
pr_err("%s: err: num_fds = %d exceeds max value\n",
|
||||
__func__, map_buf.num_fds);
|
||||
err = -EINVAL;
|
||||
goto exit_free_qcedev_areq;
|
||||
}
|
||||
|
|
@ -1956,6 +1958,12 @@ long qcedev_ioctl(struct file *file,
|
|||
err = -EFAULT;
|
||||
goto exit_free_qcedev_areq;
|
||||
}
|
||||
if (unmap_buf.num_fds > ARRAY_SIZE(unmap_buf.fd)) {
|
||||
pr_err("%s: err: num_fds = %d exceeds max value\n",
|
||||
__func__, unmap_buf.num_fds);
|
||||
err = -EINVAL;
|
||||
goto exit_free_qcedev_areq;
|
||||
}
|
||||
|
||||
for (i = 0; i < unmap_buf.num_fds; i++) {
|
||||
err = qcedev_check_and_unmap_buffer(handle,
|
||||
|
|
|
|||
Loading…
Reference in a new issue