From 3ae07bc5589b369ee42659ce745db845bdd4ef1e Mon Sep 17 00:00:00 2001 From: Gaurav Kashyap Date: Mon, 12 Sep 2022 11:28:15 +0530 Subject: [PATCH] qcedev: check num_fds during unmap check the num_fds passed into unmap buf ioctl, or else it can lead to an out of bounds access. Test: Build compilation. qcedev tests. Change-Id: I206ba01dfa989346ade769a0f68b372b21f84043 Signed-off-by: Gaurav Kashyap Signed-off-by: Pranav Lavhate --- drivers/crypto/msm/qcedev.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/drivers/crypto/msm/qcedev.c b/drivers/crypto/msm/qcedev.c index 6221510f7997..d81ce43e3fd6 100644 --- a/drivers/crypto/msm/qcedev.c +++ b/drivers/crypto/msm/qcedev.c @@ -1916,7 +1916,9 @@ long qcedev_ioctl(struct file *file, goto exit_free_qcedev_areq; } - if (map_buf.num_fds > QCEDEV_MAX_BUFFERS) { + if (map_buf.num_fds > ARRAY_SIZE(map_buf.fd)) { + pr_err("%s: err: num_fds = %d exceeds max value\n", + __func__, map_buf.num_fds); err = -EINVAL; goto exit_free_qcedev_areq; } @@ -1956,6 +1958,12 @@ long qcedev_ioctl(struct file *file, err = -EFAULT; goto exit_free_qcedev_areq; } + if (unmap_buf.num_fds > ARRAY_SIZE(unmap_buf.fd)) { + pr_err("%s: err: num_fds = %d exceeds max value\n", + __func__, unmap_buf.num_fds); + err = -EINVAL; + goto exit_free_qcedev_areq; + } for (i = 0; i < unmap_buf.num_fds; i++) { err = qcedev_check_and_unmap_buffer(handle,