From a2c6b2bcf1d25753b2701366a8df9ce65c86e665 Mon Sep 17 00:00:00 2001 From: sumap Date: Fri, 24 May 2024 16:39:50 +0530 Subject: [PATCH] dsp: q6voice: Adds checks for an integer overflow there is no check for cvs_voc_pkt[2],when recieves 0xffffffff from ADSP which results in an integer overflow Fix is to address this. Change-Id: Ie935dd8823981ec260d77f5117f4ef0b0fc08f60 Signed-off-by: Ramireddy KrishnaKanth Reddy (cherry picked from commit 4c2ad8cb15da5414979a34ea78f687664f618c4d) --- dsp/q6voice.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/dsp/q6voice.c b/dsp/q6voice.c index 769fb9ff41a3..23bc780a6932 100644 --- a/dsp/q6voice.c +++ b/dsp/q6voice.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2012-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023, Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024, Qualcomm Innovation Center, Inc. All rights reserved. */ #include #include @@ -8093,7 +8093,7 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv) VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_READY) { int ret = 0; u16 cvs_handle; - uint32_t *cvs_voc_pkt; + uint32_t *cvs_voc_pkt, tot_buf_sz; struct cvs_enc_buffer_consumed_cmd send_enc_buf_consumed_cmd; void *apr_cvs; @@ -8122,9 +8122,14 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv) VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_CONSUMED; cvs_voc_pkt = v->shmem_info.sh_buf.buf[1].data; + + if (__builtin_add_overflow(cvs_voc_pkt[2], 3 * sizeof(uint32_t), &tot_buf_sz)) { + pr_err("%s: integer overflow detected\n", __func__); + return -EINVAL; + } + if (cvs_voc_pkt != NULL && common.mvs_info.ul_cb != NULL) { - if (v->shmem_info.sh_buf.buf[1].size < - ((3 * sizeof(uint32_t)) + cvs_voc_pkt[2])) { + if (v->shmem_info.sh_buf.buf[1].size < tot_buf_sz) { pr_err("%s: invalid voc pkt size\n", __func__); return -EINVAL; }