mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 21:59:12 -04:00
asoc: handle heap overflow in effect driver
adds a variable prev_config_param_length to track the previous configuration parameter length. This is initialized to 0 and updated after processing the EQ_CONFIG command. This allows the function to compare the current and previous configuration parameter lengths to determine if memory reallocation is necessary. Change-Id: Ib03406b862b6299c421840cc193760096e2db5d9 (cherry picked from commit f770020be262cc1470eea0ce5261e08c74685764)
This commit is contained in:
parent
469e600330
commit
62a5619606
1 changed files with 11 additions and 3 deletions
|
|
@ -1,6 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/* Copyright (c) 2013-2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2023, Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
|
||||
*/
|
||||
|
||||
#include <linux/slab.h>
|
||||
|
|
@ -1091,7 +1092,7 @@ int msm_audio_effects_popless_eq_handler(struct audio_client *ac,
|
|||
u32 packed_data_size = 0;
|
||||
u8 *eq_config_data = NULL;
|
||||
u32 *updt_config_data = NULL;
|
||||
int config_param_length;
|
||||
int config_param_length, prev_config_param_length = 0;
|
||||
|
||||
pr_debug("%s\n", __func__);
|
||||
if (!ac || (devices == -EINVAL) || (num_commands == -EINVAL)) {
|
||||
|
|
@ -1211,7 +1212,12 @@ int msm_audio_effects_popless_eq_handler(struct audio_client *ac,
|
|||
if (!eq_config_data)
|
||||
eq_config_data = kzalloc(config_param_length,
|
||||
GFP_KERNEL);
|
||||
else
|
||||
else if (config_param_length != prev_config_param_length) {
|
||||
if (eq_config_data)
|
||||
kfree(eq_config_data);
|
||||
eq_config_data = kzalloc(config_param_length,
|
||||
GFP_KERNEL);
|
||||
} else
|
||||
memset(eq_config_data, 0, config_param_length);
|
||||
if (!eq_config_data) {
|
||||
pr_err("%s, EQ_CONFIG:memory alloc failed\n",
|
||||
|
|
@ -1238,6 +1244,7 @@ int msm_audio_effects_popless_eq_handler(struct audio_client *ac,
|
|||
*updt_config_data++ =
|
||||
eq->per_band_cfg[idx].band_idx;
|
||||
}
|
||||
prev_config_param_length = config_param_length;
|
||||
break;
|
||||
case EQ_BAND_INDEX:
|
||||
if (length != 1 || index_offset != 0) {
|
||||
|
|
@ -1320,7 +1327,8 @@ int msm_audio_effects_popless_eq_handler(struct audio_client *ac,
|
|||
pr_debug("%s: did not send pp params\n", __func__);
|
||||
invalid_config:
|
||||
kfree(params);
|
||||
kfree(eq_config_data);
|
||||
if (eq_config_data)
|
||||
kfree(eq_config_data);
|
||||
return rc;
|
||||
}
|
||||
EXPORT_SYMBOL(msm_audio_effects_popless_eq_handler);
|
||||
|
|
|
|||
Loading…
Reference in a new issue