From acf2f0eb6a4aabcfae75f869af836cdc30f29419 Mon Sep 17 00:00:00 2001 From: Kaushal Hooda Date: Thu, 1 Jun 2023 23:45:30 +0530 Subject: [PATCH] rpmsg: slatecom: Discard unaligned packet to read If intent_alloc_size and chunk size are unaligned with the minimum offset, then ahb_read can lead to bytes overflow as ahb_read is performed with word_size aligned. If the received chunk_size is not aligned to word_size, discard packet to read. Change-Id: Iae2c87636675da653bd182ac082a285b699e0a83 Signed-off-by: Kaushal Hooda --- drivers/rpmsg/qcom_glink_slatecom.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/drivers/rpmsg/qcom_glink_slatecom.c b/drivers/rpmsg/qcom_glink_slatecom.c index e2a4f49042cf..d57adfa3c92f 100644 --- a/drivers/rpmsg/qcom_glink_slatecom.c +++ b/drivers/rpmsg/qcom_glink_slatecom.c @@ -1694,12 +1694,21 @@ static int glink_slatecom_rx_data(struct glink_slatecom *glink, if (intent->size - intent->offset < chunk_size) { dev_err(glink->dev, "Insufficient space in intent\n"); + glink_slatecom_free_intent(channel, intent); mutex_unlock(&channel->intent_lock); /* The packet header lied, drop payload */ return msglen; } + if (chunk_size % WORD_SIZE) { + dev_err(glink->dev, "For chunk_size %d use short packet\n", + chunk_size); + glink_slatecom_free_intent(channel, intent); + mutex_unlock(&channel->intent_lock); + return -EBADMSG; + } + rc = slatecom_ahb_read(glink->slatecom_handle, (uint32_t)(size_t)addr, ALIGN(chunk_size, WORD_SIZE)/WORD_SIZE, intent->data + intent->offset);