msm: adsprpc: Add checks to avoid buffer overflow

Do integer overflow check on the length of buffer
to be copied before copying to the buffer.

Change-Id: I425861170125fb3069739af84975c4893462624e
Acked-by: Chenna Kesava Raju <chennak@qti.qualcomm.com>
Signed-off-by: Jeya R <jeyr@codeaurora.org>`
This commit is contained in:
Jeya R 2021-03-23 14:47:40 +05:30
commit a13f71e81a

View file

@ -2230,7 +2230,7 @@ static int get_args(uint32_t kernel, struct smq_invoke_ctx *ctx)
int outbufs = REMOTE_SCALARS_OUTBUFS(sc);
int handles, bufs = inbufs + outbufs;
uintptr_t args = 0;
size_t rlen = 0, copylen = 0, metalen = 0, lrpralen = 0;
size_t rlen = 0, copylen = 0, metalen = 0, lrpralen = 0, templen = 0;
size_t totallen = 0; //header and non ion copy buf len
int i, oix;
int err = 0, j = 0;
@ -2328,12 +2328,13 @@ static int get_args(uint32_t kernel, struct smq_invoke_ctx *ctx)
copylen = ALIGN(copylen, BALIGN);
mstart = ctx->overps[oix]->mstart;
mend = ctx->overps[oix]->mend;
VERIFY(err, (mend - mstart) <= LONG_MAX);
templen = mend - mstart;
VERIFY(err, ((templen <= LONG_MAX) && (copylen <= (LONG_MAX - templen))));
if (err) {
err = -EFAULT;
goto bail;
}
copylen += mend - mstart;
copylen += templen;
}
totallen = ALIGN(totallen, BALIGN) + copylen;