msm: cvp: avoid OOB write while accessing memory

Exclude 4 bytes which holds the size of the buffer while calculating
the actual buffer size to avoid OOB write.

Change-Id: I79704181e0bafc905064621d7cd6e682cca15982
Signed-off-by: suchawla <suchawla@codeaurora.org>
Signed-off-by: Govindaraj Rajagopal <grajagop@codeaurora.org>
This commit is contained in:
Govindaraj Rajagopal 2020-02-20 11:30:40 +05:30 • committed by suchawla
commit 4267dcfae7

View file

@ -2673,20 +2673,26 @@ skip_power_off:
return -EAGAIN;
}
static void __process_sys_error(struct iris_hfi_device *device)
static void print_sfr_message(struct iris_hfi_device *device)
{
struct cvp_hfi_sfr_struct *vsfr = NULL;
u32 vsfr_size = 0;
void *p = NULL;
vsfr = (struct cvp_hfi_sfr_struct *)device->sfr.align_virtual_addr;
if (vsfr) {
void *p = memchr(vsfr->rg_data, '\0', vsfr->bufSize);
if (vsfr->bufSize != device->sfr.mem_size) {
dprintk(CVP_ERR, "Invalid SFR buf size %d actual %d\n",
vsfr->bufSize, device->sfr.mem_size);
return;
}
vsfr_size = vsfr->bufSize - sizeof(u32);
p = memchr(vsfr->rg_data, '\0', vsfr_size);
/*
* SFR isn't guaranteed to be NULL terminated
* since SYS_ERROR indicates that Iris is in the
* process of crashing.
*/
if (p == NULL)
vsfr->rg_data[vsfr->bufSize - 1] = '\0';
vsfr->rg_data[vsfr_size - 1] = '\0';
dprintk(CVP_ERR, "SFR Message from FW: %s\n",
vsfr->rg_data);
@ -2810,7 +2816,7 @@ static void process_system_msg(struct msm_cvp_cb_info *info,
switch (info->response_type) {
case HAL_SYS_ERROR:
__process_sys_error(device);
print_sfr_message(device);
break;
case HAL_SYS_RELEASE_RESOURCE_DONE:
dprintk(CVP_DBG, "Received SYS_RELEASE_RESOURCE\n");
@ -2919,8 +2925,6 @@ static int __response_handler(struct iris_hfi_device *device)
}
if (device->intr_status & CVP_FATAL_INTR_BMSK) {
struct cvp_hfi_sfr_struct *vsfr = (struct cvp_hfi_sfr_struct *)
device->sfr.align_virtual_addr;
struct msm_cvp_cb_info info = {
.response_type = HAL_SYS_WATCHDOG_TIMEOUT,
.response.cmd = {
@ -2928,9 +2932,7 @@ static int __response_handler(struct iris_hfi_device *device)
}
};
if (vsfr)
dprintk(CVP_ERR, "SFR Message from FW: %s\n",
vsfr->rg_data);
print_sfr_message(device);
if (device->intr_status & CVP_WRAPPER_INTR_MASK_CPU_NOC_BMSK)
dprintk(CVP_ERR, "Received Xtensa NOC error\n");