From 542be35e0e4883f60bd4839364eb6c142e96858b Mon Sep 17 00:00:00 2001 From: Parag Singhal Date: Wed, 17 Jun 2026 10:57:44 +0530 Subject: [PATCH] msm: camera: common: Fix OOB access in bandwidth path handling Invalid input from user can lead to an index going below the valid range after offset calculation. Existing validation only checked the upper bound, allowing negative values to pass and cause out-of-bounds memory access. Add complete bounds validation to ensure safe access. CRs-Fixed: 4544133 Change-Id: Ib37b25ab84e9004eaeb216302857d65df18a2516 Signed-off-by: Parag Singhal (cherry picked from commit d6cee3f552be8126f0c8b29ea833228bf3357fa8) --- drivers/cam_ope/ope_hw_mgr/cam_ope_hw_mgr.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/drivers/cam_ope/ope_hw_mgr/cam_ope_hw_mgr.c b/drivers/cam_ope/ope_hw_mgr/cam_ope_hw_mgr.c index 31cad8f760a8..d4137ef50e5f 100644 --- a/drivers/cam_ope/ope_hw_mgr/cam_ope_hw_mgr.c +++ b/drivers/cam_ope/ope_hw_mgr/cam_ope_hw_mgr.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2017-2022, The Linux Foundation. All rights reserved. - * Copyright (c) 2023-2024 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. */ #include @@ -783,7 +783,7 @@ static int32_t cam_ope_process_request_timer(void *priv, void *data) .path_data_type - CAM_AXI_PATH_DATA_OPE_START_OFFSET; - if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { + if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { CAM_WARN(CAM_OPE, "Invalid path %d, start offset=%d, max=%d", ctx_data->clk_info.axi_path[i] @@ -1466,7 +1466,7 @@ static bool cam_ope_update_bw_v2(struct cam_ope_hw_mgr *hw_mgr, ctx_data->clk_info.axi_path[i].path_data_type - CAM_AXI_PATH_DATA_OPE_START_OFFSET; - if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { + if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { CAM_WARN(CAM_OPE, "Invalid path %d, start offset=%d, max=%d", ctx_data->clk_info.axi_path[i].path_data_type, @@ -1503,7 +1503,7 @@ static bool cam_ope_update_bw_v2(struct cam_ope_hw_mgr *hw_mgr, ctx_data->clk_info.axi_path[i].path_data_type - CAM_AXI_PATH_DATA_OPE_START_OFFSET; - if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { + if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { CAM_WARN(CAM_OPE, "Invalid path %d, start offset=%d, max=%d", ctx_data->clk_info.axi_path[i].path_data_type, @@ -2899,7 +2899,7 @@ static int cam_ope_mgr_remove_bw(struct cam_ope_hw_mgr *hw_mgr, int ctx_id) ctx_data->clk_info.axi_path[i].path_data_type - CAM_AXI_PATH_DATA_OPE_START_OFFSET; - if (path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { + if (path_index < 0 || path_index >= CAM_OPE_MAX_PER_PATH_VOTES) { CAM_WARN(CAM_OPE, "Invalid path %d, start offset=%d, max=%d", ctx_data->clk_info.axi_path[i].path_data_type,