dsp: q6lsm: Address use after free for mmap handle

The global declared mmap_handle can be left dangling
for case when the handle is freed by the calling function.
Fix is to address this. Also add a check to make sure
the mmap_handle is accessed legally.

Mot-CRs-fixed: (CR)
CVE-Fixed: CVE-2023-33120
CRs-Fixed: 3538938
Change-Id: I367f8a41339aa0025b545b125ee820220efedeee
Signed-off-by: Soumya Managoli <quic_c_smanag@quicinc.com>
Signed-off-by: Ashutosh Verma <ashverma@motorola.com>
Reviewed-on: https://gerrit.mot.com/2761210
SME-Granted: SME Approvals Granted
SLTApproved: Slta Waiver
Tested-by: Jira Key
Reviewed-by: Hujun Liao <liaohj@motorola.com>
Submit-Approved: Jira Key
This commit is contained in:
Sandhya Mutha Naga Venkata 2023-07-20 14:40:44 +05:30 • committed by panyq6
commit 641e93631b

View file

@ -539,6 +539,7 @@ static int q6lsm_apr_send_pkt(struct lsm_client *client, void *handle,
if (wait)
mutex_unlock(&lsm_common.apr_lock);
mmap_handle_p = NULL;
if (mmap_p && *mmap_p == 0)
ret = -ENOMEM;
mmap_handle_p = NULL;