qcedev: check num_fds during unmap

check the num_fds passed into unmap buf ioctl,
or else it can lead to an out of bounds access.

Test: Build compilation. qcedev tests.

Change-Id: I206ba01dfa989346ade769a0f68b372b21f84043
Signed-off-by: Gaurav Kashyap <quic_gaurkash@quicinc.com>
Signed-off-by: Pranav Lavhate <quic_plavhate@quicinc.com>
This commit is contained in:
Gaurav Kashyap 2022-09-12 11:28:15 +05:30 • committed by Gerrit - the friendly Code Review server
commit 3ae07bc558

View file

@ -1916,7 +1916,9 @@ long qcedev_ioctl(struct file *file,
goto exit_free_qcedev_areq;
}
if (map_buf.num_fds > QCEDEV_MAX_BUFFERS) {
if (map_buf.num_fds > ARRAY_SIZE(map_buf.fd)) {
pr_err("%s: err: num_fds = %d exceeds max value\n",
__func__, map_buf.num_fds);
err = -EINVAL;
goto exit_free_qcedev_areq;
}
@ -1956,6 +1958,12 @@ long qcedev_ioctl(struct file *file,
err = -EFAULT;
goto exit_free_qcedev_areq;
}
if (unmap_buf.num_fds > ARRAY_SIZE(unmap_buf.fd)) {
pr_err("%s: err: num_fds = %d exceeds max value\n",
__func__, unmap_buf.num_fds);
err = -EINVAL;
goto exit_free_qcedev_areq;
}
for (i = 0; i < unmap_buf.num_fds; i++) {
err = qcedev_check_and_unmap_buffer(handle,