mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-06 03:45:24 -04:00
Merge tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina
"LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0" * tag 'LA.UM.9.14.r1-24900-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel: dsp: q6lsm: Check size of payload before access Change-Id: I782131a810aaecf254b92d94e2db252c3741784e
This commit is contained in:
commit
7262b988ea
1 changed files with 11 additions and 1 deletions
|
|
@ -2129,8 +2129,18 @@ static int q6lsm_mmapcallback(struct apr_client_data *data, void *priv)
|
|||
lsm_common.set_custom_topology = 1;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/*
|
||||
The payload_size can be either 4 or 8 bytes.
|
||||
It has to be verified whether the payload_size is
|
||||
atleast 4 bytes. If it is less, returns errorcode.
|
||||
|
||||
if (data->payload_size < (2 * sizeof(uint32_t))) {
|
||||
The opcode for 4 bytes is 0x12A80
|
||||
The opcode for 8 bytes is 0x110E8.
|
||||
|
||||
*/
|
||||
|
||||
if (data->payload_size < (2 * sizeof(uint16_t))) {
|
||||
pr_err("%s: payload has invalid size[%d]\n", __func__,
|
||||
data->payload_size);
|
||||
return -EINVAL;
|
||||
|
|
|
|||
Loading…
Reference in a new issue