From a7f46c9cb7ddaa6331d80328126abe6d8ab4155d Mon Sep 17 00:00:00 2001 From: Jeya R Date: Thu, 31 Dec 2020 17:03:46 +0530 Subject: [PATCH] msm:ADSPRPC :Fix to avoid Use after free in fastrpc_internal_munmap Added a check to validate map before freeing it to avoid Use after free scenario. Change-Id: I484391ff7c55c0689530a928a2821ee5a1a0e10c Signed-off-by: Jeya R --- drivers/char/adsprpc.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c index 0e57f56ee7ba..dc6c1d6d8b15 100644 --- a/drivers/char/adsprpc.c +++ b/drivers/char/adsprpc.c @@ -4498,8 +4498,13 @@ static int fastrpc_internal_munmap(struct fastrpc_file *fl, mutex_unlock(&fl->map_mutex); if (err) goto bail; + VERIFY(err, map != NULL); + if (err) { + err = -EINVAL; + goto bail; + } VERIFY(err, !(err = fastrpc_munmap_on_dsp(fl, map->raddr, - map->phys, map->size, map->flags))); + map->phys, map->size, map->flags))); if (err) goto bail; mutex_lock(&fl->map_mutex);