From b90e90c3563e4ecdbbe0edf0d28ede2677945719 Mon Sep 17 00:00:00 2001 From: Hemant Kumar Date: Thu, 6 Feb 2020 17:32:38 -0800 Subject: [PATCH] mhi: core: Add range check for channel id received in event ring The mhi_process_data_event_ring function reads cmd channel id from cmd_pkt using MHI_TRE_GET_CHID, the value is under the control of MHI devices and can be any value between 0 and 255. However the max channel is defined in device tree file and it is usually smaller than 255. This can cause out of bound access to the channel array. Fix this by checking the channel id received in cmd ring against the max channel allowed on target. Change-Id: Iae4282ebba2976a26c6e33477cc8dd93929c2f63 Signed-off-by: Hemant Kumar --- drivers/bus/mhi/core/mhi_main.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/bus/mhi/core/mhi_main.c b/drivers/bus/mhi/core/mhi_main.c index fac3dab5e382..1f6b776964fe 100644 --- a/drivers/bus/mhi/core/mhi_main.c +++ b/drivers/bus/mhi/core/mhi_main.c @@ -1417,6 +1417,10 @@ int mhi_process_data_event_ring(struct mhi_controller *mhi_cntrl, local_rp->ptr, local_rp->dword[0], local_rp->dword[1]); chan = MHI_TRE_GET_EV_CHID(local_rp); + if (chan >= mhi_cntrl->max_chan) { + MHI_ERR("invalid channel id %u\n", chan); + continue; + } mhi_chan = &mhi_cntrl->mhi_chan[chan]; if (likely(type == MHI_PKT_TYPE_TX_EVENT)) {