From 7ce6eef9ba291d6dec586cce7373540a041b2dba Mon Sep 17 00:00:00 2001 From: Jishnu Prakash Date: Tue, 21 Nov 2023 11:42:06 +0530 Subject: [PATCH] input: misc: Validate input pattern count in pattern_s_dbgfs_write Add a check for number of input patterns detected in string read from userspace in pattern_s_dbgfs_write() API, to avoid out-of-bounds write in a local array. Change-Id: Ic35561ae34f95c67fbd54ae4db4a7174342f45f4 Signed-off-by: Jishnu Prakash --- drivers/input/misc/qcom-hv-haptics.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/input/misc/qcom-hv-haptics.c b/drivers/input/misc/qcom-hv-haptics.c index 029970344159..7f79ba9af213 100644 --- a/drivers/input/misc/qcom-hv-haptics.c +++ b/drivers/input/misc/qcom-hv-haptics.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2020-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2023, Qualcomm Innovation Center, Inc. All rights reserved. */ #include @@ -3035,6 +3035,11 @@ static ssize_t pattern_s_dbgfs_write(struct file *fp, goto exit; } + if (i >= ARRAY_SIZE(tmp)) { + pr_err("too many patterns in input string\n"); + rc = -EINVAL; + goto exit; + } tmp[i++] = val; }