From c3f431c2c71092950f625e5869fa418bbe09463f Mon Sep 17 00:00:00 2001 From: Manish Kumar Date: Mon, 10 Feb 2025 17:11:38 +0530 Subject: [PATCH] dsp: q6adm: Checking array sizeof channel_type there is no check for size of num_channels is less than are equal to channel_type Change-Id: I066857d693665412c52dc579f69acdaac66d5903 Signed-off-by: Manish Kumar --- dsp/q6adm.c | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/dsp/q6adm.c b/dsp/q6adm.c index 7455252e2f08..6000c77331e1 100644 --- a/dsp/q6adm.c +++ b/dsp/q6adm.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2012-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023, 2025 Qualcomm Innovation Center, Inc. All rights reserved. */ #include #include @@ -3910,10 +3910,14 @@ void adm_copp_mfc_cfg(int port_id, int copp_idx, int dst_sample_rate) pr_err("%s: unable to get channal map\n", __func__); goto fail_cmd; } - - for (i = 0; i < mfc_cfg.num_channels; i++) - mfc_cfg.channel_type[i] = + if (mfc_cfg.num_channels <= AUDPROC_MFC_OUT_CHANNELS_MAX) { + for (i = 0; i < mfc_cfg.num_channels; i++) + mfc_cfg.channel_type[i] = (uint16_t) open.dev_channel_mapping[i]; + } else { + pr_err("%s: size of num_channels is greater than channel type \n", __func__); + goto fail_cmd; + } atomic_set(&this_adm.copp.stat[port_idx][copp_idx], -1);