mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 22:40:54 -04:00
crypto: qcedev - fix UAF in crypto-qti driver
userspace to QCEDEV_IOCTL_MAP_BUF_REQ and QCEDEV_IOCTL_UNMAP_BUF_REQ, which can have a race condition resulting in a use-after-free (UAF). Change-Id: Iff51a098bbf9746e256e40a20fc37c5404f8aa22 Signed-off-by: Vishakha Malik <quic_vmallik@quicinc.com>
This commit is contained in:
parent
1227bcf0b1
commit
4f37e589d9
1 changed files with 7 additions and 7 deletions
|
|
@ -329,10 +329,6 @@ int qcedev_check_and_map_buffer(void *handle,
|
|||
mapped_size = binfo->ion_buf.mapped_buf_size;
|
||||
atomic_inc(&binfo->ref_count);
|
||||
|
||||
/* Add buffer mapping information to regd buffer list */
|
||||
mutex_lock(&qce_hndl->registeredbufs.lock);
|
||||
list_add_tail(&binfo->list, &qce_hndl->registeredbufs.list);
|
||||
mutex_unlock(&qce_hndl->registeredbufs.lock);
|
||||
}
|
||||
|
||||
/* Make sure the offset is within the mapped range */
|
||||
|
|
@ -344,6 +340,13 @@ int qcedev_check_and_map_buffer(void *handle,
|
|||
goto unmap;
|
||||
}
|
||||
|
||||
if (!found) {
|
||||
/* Add buffer mapping information to regd buffer list */
|
||||
mutex_lock(&qce_hndl->registeredbufs.lock);
|
||||
list_add_tail(&binfo->list, &qce_hndl->registeredbufs.list);
|
||||
mutex_unlock(&qce_hndl->registeredbufs.lock);
|
||||
}
|
||||
|
||||
/* return the mapped virtual address adjusted by offset */
|
||||
*vaddr += offset;
|
||||
|
||||
|
|
@ -352,9 +355,6 @@ int qcedev_check_and_map_buffer(void *handle,
|
|||
unmap:
|
||||
if (!found) {
|
||||
qcedev_unmap_buffer(handle, mem_client, binfo);
|
||||
mutex_lock(&qce_hndl->registeredbufs.lock);
|
||||
list_del(&binfo->list);
|
||||
mutex_unlock(&qce_hndl->registeredbufs.lock);
|
||||
}
|
||||
|
||||
error:
|
||||
|
|
|
|||
Loading…
Reference in a new issue