From 87a7aa0e83bf7d49c3fa260bc825e310d04ba192 Mon Sep 17 00:00:00 2001 From: DEEPAK SANNAPAREDDY Date: Wed, 4 Oct 2023 14:53:03 +0530 Subject: [PATCH] msm: adsprpc : Fix use after free in fastrpc_internal_mem_unmap Thread 1 can make a to call fastrpc_mmap_create under internal mem map and release fl->map_mutex. Thread 2 can make call to internal mem unmap, acquire fl->map_mutex and get same map though fastrpc_mmap_remove. Thread 1 fail in fastrpc_mem_map_to_dsp jumps to bail and do map free. Thread 2 still holds same map which can lead use after free. Serialize fastrpc internal mem map and unmap. Mot-CRs-fixed: (CR) CVE-Fixed: CVE-2023-43514 CRs-Fixed: 3613254 Bug: 303101664 Change-Id: I54a3602914b43fc67635c0de193bd21aa13daaa3 Signed-off-by: DEEPAK SANNAPAREDDY Signed-off-by: Ashutosh Verma Reviewed-on: https://gerrit.mot.com/2832044 SLTApproved: Slta Waiver SME-Granted: SME Approvals Granted Tested-by: Jira Key Reviewed-by: Chakradhar Gajjala Reviewed-by: Xiangpo Zhao Submit-Approved: Jira Key --- drivers/char/adsprpc.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c index 8e7b4eff7325..9268f39cb328 100644 --- a/drivers/char/adsprpc.c +++ b/drivers/char/adsprpc.c @@ -4959,6 +4959,7 @@ static int fastrpc_internal_mem_map(struct fastrpc_file *fl, int err = 0; struct fastrpc_mmap *map = NULL; + mutex_lock(&fl->internal_map_mutex); VERIFY(err, fl->dsp_proc_init == 1); if (err) { pr_err("adsprpc: ERROR: %s: user application %s trying to map without initialization\n", @@ -4997,6 +4998,7 @@ bail: mutex_unlock(&fl->map_mutex); } } + mutex_unlock(&fl->internal_map_mutex); return err; } @@ -5006,6 +5008,7 @@ static int fastrpc_internal_mem_unmap(struct fastrpc_file *fl, int err = 0; struct fastrpc_mmap *map = NULL; + mutex_lock(&fl->internal_map_mutex); VERIFY(err, fl->dsp_proc_init == 1); if (err) { pr_err("adsprpc: ERROR: %s: user application %s trying to map without initialization\n", @@ -5051,6 +5054,7 @@ bail: mutex_unlock(&fl->map_mutex); } } + mutex_unlock(&fl->internal_map_mutex); return err; }