mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-11 07:03:09 -04:00
mhi: core: Add range check for channel id received in event ring
The mhi_process_data_event_ring function reads cmd channel id from cmd_pkt using MHI_TRE_GET_CHID, the value is under the control of MHI devices and can be any value between 0 and 255. However the max channel is defined in device tree file and it is usually smaller than 255. This can cause out of bound access to the channel array. Fix this by checking the channel id received in cmd ring against the max channel allowed on target. Change-Id: Iae4282ebba2976a26c6e33477cc8dd93929c2f63 Signed-off-by: Hemant Kumar <hemantk@codeaurora.org>
This commit is contained in:
parent
0179be9121
commit
b90e90c356
1 changed files with 4 additions and 0 deletions
|
|
@ -1417,6 +1417,10 @@ int mhi_process_data_event_ring(struct mhi_controller *mhi_cntrl,
|
|||
local_rp->ptr, local_rp->dword[0], local_rp->dword[1]);
|
||||
|
||||
chan = MHI_TRE_GET_EV_CHID(local_rp);
|
||||
if (chan >= mhi_cntrl->max_chan) {
|
||||
MHI_ERR("invalid channel id %u\n", chan);
|
||||
continue;
|
||||
}
|
||||
mhi_chan = &mhi_cntrl->mhi_chan[chan];
|
||||
|
||||
if (likely(type == MHI_PKT_TYPE_TX_EVENT)) {
|
||||
|
|
|
|||
Loading…
Reference in a new issue