mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-05 19:31:57 -04:00
dsp: q6lsm: Address use after free for mmap handle
The global declared mmap_handle can be left dangling for case when the handle is freed by the calling function. Fix is to address this. Also add a check to make sure the mmap_handle is accessed legally. Mot-CRs-fixed: (CR) CVE-Fixed: CVE-2023-33120 CRs-Fixed: 3538938 Change-Id: I367f8a41339aa0025b545b125ee820220efedeee Signed-off-by: Soumya Managoli <quic_c_smanag@quicinc.com> Signed-off-by: Ashutosh Verma <ashverma@motorola.com> Reviewed-on: https://gerrit.mot.com/2761210 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Hujun Liao <liaohj@motorola.com> Submit-Approved: Jira Key
This commit is contained in:
parent
27ad5dd6a9
commit
641e93631b
1 changed files with 1 additions and 0 deletions
|
|
@ -539,6 +539,7 @@ static int q6lsm_apr_send_pkt(struct lsm_client *client, void *handle,
|
|||
if (wait)
|
||||
mutex_unlock(&lsm_common.apr_lock);
|
||||
|
||||
mmap_handle_p = NULL;
|
||||
if (mmap_p && *mmap_p == 0)
|
||||
ret = -ENOMEM;
|
||||
mmap_handle_p = NULL;
|
||||
|
|
|
|||
Loading…
Reference in a new issue