From 14c551f6abb3ad841accc8af91c4a18c0a78b2fe Mon Sep 17 00:00:00 2001 From: Shaik Jabida Date: Mon, 1 Jul 2024 14:27:21 +0530 Subject: [PATCH] dsp: q6lsm: Check size of payload before access check size of payload before access in q6lsm_mmapcallback. The payload size can be either 4 or 8 bytes. Code to verify the payload size is atleast 4 bytes is added. Change-Id: I64b07f44b66fe6793bc80bc99a09fd0521342531 Signed-off-by: Shaik Jabida --- dsp/q6lsm.c | 12 +++++++++++- 1 file changed, 11 insertions(+), 1 deletion(-) diff --git a/dsp/q6lsm.c b/dsp/q6lsm.c index 175c8fcb1a7e..aa4127c1ae82 100644 --- a/dsp/q6lsm.c +++ b/dsp/q6lsm.c @@ -2129,8 +2129,18 @@ static int q6lsm_mmapcallback(struct apr_client_data *data, void *priv) lsm_common.set_custom_topology = 1; return 0; } + + /* + The payload_size can be either 4 or 8 bytes. + It has to be verified whether the payload_size is + atleast 4 bytes. If it is less, returns errorcode. - if (data->payload_size < (2 * sizeof(uint32_t))) { + The opcode for 4 bytes is 0x12A80 + The opcode for 8 bytes is 0x110E8. + + */ + + if (data->payload_size < (2 * sizeof(uint16_t))) { pr_err("%s: payload has invalid size[%d]\n", __func__, data->payload_size); return -EINVAL;