From 98f4a2d9320639183ebc8957c5540e1767658158 Mon Sep 17 00:00:00 2001 From: Gaurav Singh Date: Wed, 14 Apr 2021 11:48:13 +0530 Subject: [PATCH] drivers: soc: qcom: msm_performance: Add NULL check in PLH function Added NULL pointer check in PLH command string parsing function. Change-Id: I1a4ef2364a36188dd5b189f6ee6cb77fe7e185c4 Signed-off-by: Gaurav Singh --- drivers/soc/qcom/msm_performance.c | 19 ++++++++++++++++--- 1 file changed, 16 insertions(+), 3 deletions(-) diff --git a/drivers/soc/qcom/msm_performance.c b/drivers/soc/qcom/msm_performance.c index 506bbdf5ce2d..8f735f4ab21f 100644 --- a/drivers/soc/qcom/msm_performance.c +++ b/drivers/soc/qcom/msm_performance.c @@ -1,6 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* - * Copyright (c) 2016-2020, The Linux Foundation. All rights reserved. + * Copyright (c) 2016-2021, The Linux Foundation. All rights reserved. */ #include @@ -1009,6 +1009,8 @@ static int init_splh_notif(const char *buf) cp = strnchr(cp, strlen(cp), ':'); /* skip INIT */ cp++; cp = strnchr(cp, strlen(cp), ':'); /* skip nfps */ + if (!cp) + return -EINVAL; *ptmp++ = nfps; /* nfps is first cmd param */ tmp_valid_len++; @@ -1035,6 +1037,9 @@ static int init_splh_notif(const char *buf) ptmp++; /* increment after storing FPS val */ tmp_valid_len++; cp1 = strnchr(cp1, strlen(cp1), ','); /* move to ,ipc */ + if (!cp1) + return -EINVAL; + for (j = 0; j < 2 * n_ipc_freq_pair; j++) { if (sscanf(cp1, ",%hu", ptmp) != 1) return -EINVAL; @@ -1042,12 +1047,20 @@ static int init_splh_notif(const char *buf) ptmp++; /* increment after storing ipc or freq */ tmp_valid_len++; cp1++; - if (j != (2 * n_ipc_freq_pair - 1)) + if (j != (2 * n_ipc_freq_pair - 1)) { cp1 = strnchr(cp1, strlen(cp1), ','); /* move to next */ + if (!cp1) + return -EINVAL; + + } } - if (i != (nfps - 1)) + if (i != (nfps - 1)) { cp1 = strnchr(cp1, strlen(cp1), ':'); /* move to next FPS val */ + if (!cp1) + return -EINVAL; + + } } } else {