From 7bb35d66956db9a5150ca2ed1dcdea74605ee9bd Mon Sep 17 00:00:00 2001 From: Jeya R Date: Wed, 22 Jul 2020 16:53:49 +0530 Subject: [PATCH] msm: ADSPRPC: Size check before allocating memory from DMA For allocating memory from DMA we need to do a size check. This validation is required to avoid any improper paging request. We already have the range in which the size is expected to be. Change-Id: I20a843366a7f3e3e21cef89cf1ea5bec3f93ab2d Acked-by: Ekansh Gupta Signed-off-by: Jeya R --- drivers/char/adsprpc.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c index e1b1784860ab..a2039db7dd1b 100644 --- a/drivers/char/adsprpc.c +++ b/drivers/char/adsprpc.c @@ -909,6 +909,7 @@ static int fastrpc_mmap_find(struct fastrpc_file *fl, int fd, static int fastrpc_alloc_cma_memory(dma_addr_t *region_phys, void **vaddr, size_t size, unsigned long dma_attr) { + int err = 0; struct fastrpc_apps *me = &gfa; if (me->dev == NULL) { @@ -916,6 +917,13 @@ static int fastrpc_alloc_cma_memory(dma_addr_t *region_phys, void **vaddr, "failed to allocate CMA memory, device adsprpc-mem is not initialized\n"); return -ENODEV; } + VERIFY(err, size > 0 && size < me->max_size_limit); + if (err) { + err = -EFAULT; + pr_err("adsprpc: %s: invalid allocation size 0x%zx\n", + __func__, size); + return err; + } *vaddr = dma_alloc_attrs(me->dev, size, region_phys, GFP_KERNEL, dma_attr); if (IS_ERR_OR_NULL(*vaddr)) {