mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
dsp: q6lsm: Check size of payload before access
check size of payload before access in q6lsm_mmapcallback. Change-Id: I6a755ca4cf54078f0d00f38e303f1b1da29b244c Signed-off-by: Kumar Anurag Singh <quic_kumaranu@quicinc.com>
This commit is contained in:
parent
dcd49b01ee
commit
bbe748c8df
1 changed files with 7 additions and 1 deletions
|
|
@ -1,7 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2013-2021, Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2023 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) 2023-2024 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
#include <linux/fs.h>
|
||||
#include <linux/mutex.h>
|
||||
|
|
@ -2130,6 +2130,12 @@ static int q6lsm_mmapcallback(struct apr_client_data *data, void *priv)
|
|||
return 0;
|
||||
}
|
||||
|
||||
if (data->payload_size < (2 * sizeof(uint32_t))) {
|
||||
pr_err("%s: payload has invalid size[%d]\n", __func__,
|
||||
data->payload_size);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
command = payload[0];
|
||||
retcode = payload[1];
|
||||
sid = (data->token >> 8) & 0x0F;
|
||||
|
|
|
|||
Loading…
Reference in a new issue