crypto: qcedev - fix UAF in crypto-qti driver

userspace to QCEDEV_IOCTL_MAP_BUF_REQ and
QCEDEV_IOCTL_UNMAP_BUF_REQ, which can have a race condition
resulting in a use-after-free (UAF).

Change-Id: Iff51a098bbf9746e256e40a20fc37c5404f8aa22
Signed-off-by: Vishakha Malik <quic_vmallik@quicinc.com>
This commit is contained in:
Vishakha Malik 2025-06-09 15:31:59 +05:30
commit 4f37e589d9

View file

@ -329,10 +329,6 @@ int qcedev_check_and_map_buffer(void *handle,
mapped_size = binfo->ion_buf.mapped_buf_size;
atomic_inc(&binfo->ref_count);
/* Add buffer mapping information to regd buffer list */
mutex_lock(&qce_hndl->registeredbufs.lock);
list_add_tail(&binfo->list, &qce_hndl->registeredbufs.list);
mutex_unlock(&qce_hndl->registeredbufs.lock);
}
/* Make sure the offset is within the mapped range */
@ -344,6 +340,13 @@ int qcedev_check_and_map_buffer(void *handle,
goto unmap;
}
if (!found) {
/* Add buffer mapping information to regd buffer list */
mutex_lock(&qce_hndl->registeredbufs.lock);
list_add_tail(&binfo->list, &qce_hndl->registeredbufs.list);
mutex_unlock(&qce_hndl->registeredbufs.lock);
}
/* return the mapped virtual address adjusted by offset */
*vaddr += offset;
@ -352,9 +355,6 @@ int qcedev_check_and_map_buffer(void *handle,
unmap:
if (!found) {
qcedev_unmap_buffer(handle, mem_client, binfo);
mutex_lock(&qce_hndl->registeredbufs.lock);
list_del(&binfo->list);
mutex_unlock(&qce_hndl->registeredbufs.lock);
}
error: