From bc4424fa22de774bd4c53ffbbde5874292d5b9c3 Mon Sep 17 00:00:00 2001 From: Abinath S Date: Fri, 10 May 2024 12:17:37 +0530 Subject: [PATCH] asoc: Fix out-of-bound write Modified check to avoid out-of-bound write. Change-Id: Ife5454d8de74b603291d3c129f03f1b901c6de8b Signed-off-by: Abinath S --- asoc/msm-compress-q6-v2.c | 4 ++-- asoc/msm-pcm-routing-v2.c | 5 +++-- asoc/msm-qti-pp-config.c | 3 ++- 3 files changed, 7 insertions(+), 5 deletions(-) diff --git a/asoc/msm-compress-q6-v2.c b/asoc/msm-compress-q6-v2.c index ce177a4b990f..14f549310547 100644 --- a/asoc/msm-compress-q6-v2.c +++ b/asoc/msm-compress-q6-v2.c @@ -4143,7 +4143,7 @@ static int msm_compr_channel_map_put(struct snd_kcontrol *kcontrol, pr_debug("%s: fe_id- %llu\n", __func__, fe_id); - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s Received out of bounds fe_id %llu\n", __func__, fe_id); rc = -EINVAL; @@ -4185,7 +4185,7 @@ static int msm_compr_channel_map_get(struct snd_kcontrol *kcontrol, int rc = 0, i; pr_debug("%s: fe_id- %llu\n", __func__, fe_id); - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: Received out of bounds fe_id %llu\n", __func__, fe_id); rc = -EINVAL; diff --git a/asoc/msm-pcm-routing-v2.c b/asoc/msm-pcm-routing-v2.c index d2df93bb0cc9..7fef53cada56 100644 --- a/asoc/msm-pcm-routing-v2.c +++ b/asoc/msm-pcm-routing-v2.c @@ -3,6 +3,7 @@ * * Changes from Qualcomm Innovation Center are provided under the following license: * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted (subject to the limitations in the @@ -2308,7 +2309,7 @@ static int msm_pcm_routing_channel_mixer_v2(int fe_id, bool perf_mode, int i = 0, j = 0, be_id = 0; int ret = 0; - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: invalid FE %d\n", __func__, fe_id); return 0; } @@ -2376,7 +2377,7 @@ static int msm_pcm_routing_channel_mixer(int fe_id, bool perf_mode, return ret; } - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: invalid FE %d\n", __func__, fe_id); return 0; } diff --git a/asoc/msm-qti-pp-config.c b/asoc/msm-qti-pp-config.c index cdc0f38168f5..5bac60210bf0 100644 --- a/asoc/msm-qti-pp-config.c +++ b/asoc/msm-qti-pp-config.c @@ -1,5 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. */ #include @@ -178,7 +179,7 @@ static int msm_qti_pp_put_dtmf_module_enable fe_id = ((struct soc_multi_mixer_control *) kcontrol->private_value)->shift; - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: invalid FE %d\n", __func__, fe_id); return -EINVAL; }