mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
msm: camera: common: Fix OOB access in bandwidth path handling
Invalid input from user can lead to an index going below the valid range after offset calculation. Existing validation only checked the upper bound, allowing negative values to pass and cause out-of-bounds memory access. Add complete bounds validation to ensure safe access. CRs-Fixed: 4544133 Change-Id: Ib37b25ab84e9004eaeb216302857d65df18a2516 Signed-off-by: Parag Singhal <parsin@qti.qualcomm.com> (cherry picked from commit d6cee3f552be8126f0c8b29ea833228bf3357fa8)
This commit is contained in:
parent
68c6536164
commit
542be35e0e
1 changed files with 5 additions and 5 deletions
|
|
@ -1,7 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2017-2022, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2023-2024 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
|
||||
*/
|
||||
|
||||
#include <linux/uaccess.h>
|
||||
|
|
@ -783,7 +783,7 @@ static int32_t cam_ope_process_request_timer(void *priv, void *data)
|
|||
.path_data_type -
|
||||
CAM_AXI_PATH_DATA_OPE_START_OFFSET;
|
||||
|
||||
if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
CAM_WARN(CAM_OPE,
|
||||
"Invalid path %d, start offset=%d, max=%d",
|
||||
ctx_data->clk_info.axi_path[i]
|
||||
|
|
@ -1466,7 +1466,7 @@ static bool cam_ope_update_bw_v2(struct cam_ope_hw_mgr *hw_mgr,
|
|||
ctx_data->clk_info.axi_path[i].path_data_type -
|
||||
CAM_AXI_PATH_DATA_OPE_START_OFFSET;
|
||||
|
||||
if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
CAM_WARN(CAM_OPE,
|
||||
"Invalid path %d, start offset=%d, max=%d",
|
||||
ctx_data->clk_info.axi_path[i].path_data_type,
|
||||
|
|
@ -1503,7 +1503,7 @@ static bool cam_ope_update_bw_v2(struct cam_ope_hw_mgr *hw_mgr,
|
|||
ctx_data->clk_info.axi_path[i].path_data_type -
|
||||
CAM_AXI_PATH_DATA_OPE_START_OFFSET;
|
||||
|
||||
if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
CAM_WARN(CAM_OPE,
|
||||
"Invalid path %d, start offset=%d, max=%d",
|
||||
ctx_data->clk_info.axi_path[i].path_data_type,
|
||||
|
|
@ -2899,7 +2899,7 @@ static int cam_ope_mgr_remove_bw(struct cam_ope_hw_mgr *hw_mgr, int ctx_id)
|
|||
ctx_data->clk_info.axi_path[i].path_data_type -
|
||||
CAM_AXI_PATH_DATA_OPE_START_OFFSET;
|
||||
|
||||
if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) {
|
||||
CAM_WARN(CAM_OPE,
|
||||
"Invalid path %d, start offset=%d, max=%d",
|
||||
ctx_data->clk_info.axi_path[i].path_data_type,
|
||||
|
|
|
|||
Loading…
Reference in a new issue