From 641e93631b90732d35dc32acaa8732f51d8b732d Mon Sep 17 00:00:00 2001 From: Sandhya Mutha Naga Venkata Date: Thu, 20 Jul 2023 14:40:44 +0530 Subject: [PATCH] dsp: q6lsm: Address use after free for mmap handle The global declared mmap_handle can be left dangling for case when the handle is freed by the calling function. Fix is to address this. Also add a check to make sure the mmap_handle is accessed legally. Mot-CRs-fixed: (CR) CVE-Fixed: CVE-2023-33120 CRs-Fixed: 3538938 Change-Id: I367f8a41339aa0025b545b125ee820220efedeee Signed-off-by: Soumya Managoli Signed-off-by: Ashutosh Verma Reviewed-on: https://gerrit.mot.com/2761210 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Hujun Liao Submit-Approved: Jira Key --- dsp/q6lsm.c | 1 + 1 file changed, 1 insertion(+) diff --git a/dsp/q6lsm.c b/dsp/q6lsm.c index bcb8f652ffe8..deaaa9a68f1d 100644 --- a/dsp/q6lsm.c +++ b/dsp/q6lsm.c @@ -539,6 +539,7 @@ static int q6lsm_apr_send_pkt(struct lsm_client *client, void *handle, if (wait) mutex_unlock(&lsm_common.apr_lock); + mmap_handle_p = NULL; if (mmap_p && *mmap_p == 0) ret = -ENOMEM; mmap_handle_p = NULL;