mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
msm: camera: sync: Prevent OOB access of sync name
Issue: strlcpy calls strlen on src ptr. If src is not NULL terminated then OOB access will occur in below stack. strlen strlcpy cam_sync_init_row cam_sync_handle_create cam_sync_dev_ioctl Fix: Pad user-space supplied name with NULL. CRs-Fixed: 3010262 Change-Id: Ib5c2fbfe395025ec05e0bb2980f86111e95ff54c Signed-off-by: Trishansh Bhardwaj <tbhardwa@codeaurora.org>
This commit is contained in:
parent
b7de35c284
commit
8839726f67
1 changed files with 2 additions and 1 deletions
|
|
@ -1,6 +1,6 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2017-2020, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2017-2021, The Linux Foundation. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/init.h>
|
||||
|
|
@ -477,6 +477,7 @@ static int cam_sync_handle_create(struct cam_private_ioctl_arg *k_ioctl)
|
|||
u64_to_user_ptr(k_ioctl->ioctl_ptr),
|
||||
k_ioctl->size))
|
||||
return -EFAULT;
|
||||
sync_create.name[SYNC_DEBUG_NAME_LEN] = '\0';
|
||||
|
||||
result = cam_sync_create(&sync_create.sync_obj,
|
||||
sync_create.name);
|
||||
|
|
|
|||
Loading…
Reference in a new issue