From ae431b8af0059ed10b45753fc4e7b8b147eeed19 Mon Sep 17 00:00:00 2001 From: Li Xu Date: Wed, 26 Sep 2018 11:04:40 -0500 Subject: [PATCH] ASoC: cs35l41: Add out of bound check for mixer Program such as nanomix allows out of bound input to mixer, which may crash kernel. This issue is found by Google test (LENOVO-848). Add out of bound check for mixer to prevent kernel crash. Mot-Crs-fixed:(CR) Change-Id: I4c0437cfd2d2570a9c9489db500cffc513f27c43 Signed-off-by: Li Xu Reviewed-on: https://gerrit.mot.com/1253050 SME-Granted: SME Approvals Granted SLTApproved: Slta Waiver Tested-by: Jira Key Reviewed-by: Guobin Zhang Submit-Approved: Jira Key Reviewed-on: https://gerrit.mot.com/1253083 --- sound/soc/codecs/cs35l41.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/sound/soc/codecs/cs35l41.c b/sound/soc/codecs/cs35l41.c index da03c2dfca52..c89d03633e1a 100644 --- a/sound/soc/codecs/cs35l41.c +++ b/sound/soc/codecs/cs35l41.c @@ -317,12 +317,17 @@ static int cs35l41_cspl_cmd_put(struct snd_kcontrol *kcontrol, struct cs35l41_private *cs35l41 = snd_soc_codec_get_drvdata(codec); struct soc_enum *soc_enum; unsigned int i = ucontrol->value.enumerated.item[0]; - int ret = 0; soc_enum = (struct soc_enum *)kcontrol->private_value; + + if (i >= soc_enum->items) { + dev_err(codec->dev, "Invalid mixer input (%u)\n", i); + return -EINVAL; + } + cs35l41->cspl_cmd = soc_enum->values[i]; - return ret; + return 0; } static int cs35l41_cspl_cmd_get(struct snd_kcontrol *kcontrol,