mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-08 12:58:12 -04:00
msm: kgsl: Fix overflow issue by checking user supplied count
User supplied count can cause signed integer overflow when passed to dma_fence_array_create. So make sure that count is less than INT_MAX. Change-Id: Ie6f57e06a8f23e9fdc10f8a368921b9ad3516eba Signed-off-by: Puranam V G Tejaswi <pvgtejas@codeaurora.org>
This commit is contained in:
parent
1c9badc674
commit
af84577f4b
2 changed files with 3 additions and 3 deletions
|
|
@ -23,14 +23,14 @@ struct kgsl_timeline_fence {
|
|||
};
|
||||
|
||||
struct dma_fence *kgsl_timelines_to_fence_array(struct kgsl_device *device,
|
||||
u64 timelines, u64 count, u64 usize, bool any)
|
||||
u64 timelines, u32 count, u64 usize, bool any)
|
||||
{
|
||||
void __user *uptr = u64_to_user_ptr(timelines);
|
||||
struct dma_fence_array *array;
|
||||
struct dma_fence **fences;
|
||||
int i, ret = 0;
|
||||
|
||||
if (!count)
|
||||
if (!count || count > INT_MAX)
|
||||
return ERR_PTR(-EINVAL);
|
||||
|
||||
fences = kcalloc(count, sizeof(*fences),
|
||||
|
|
|
|||
|
|
@ -108,6 +108,6 @@ static inline void kgsl_timeline_put(struct kgsl_timeline *timeline)
|
|||
* encapsulated timeline fences to expire.
|
||||
*/
|
||||
struct dma_fence *kgsl_timelines_to_fence_array(struct kgsl_device *device,
|
||||
u64 timelines, u64 count, u64 usize, bool any);
|
||||
u64 timelines, u32 count, u64 usize, bool any);
|
||||
|
||||
#endif
|
||||
|
|
|
|||
Loading…
Reference in a new issue