msm: camera: isp: Fix potential illegal access in Acquire HW

Fix potential illegal acquire_hw memory access due to following
scenario. Even though ioctl is synchronous, the kernel performs
1. copy_from_user(&api_version, ...) — reads just the version.
2. Allocates buffer based on version.
3. copy_from_user(acquire_ptr, ...) — reads the full structure.

If another thread modifies the user-space buffer (cmd->handle)
between steps 1 and 3, the kernel will
* Allocate a buffer for version 1.
* But read data formatted for version 1, by modifying api version v2.
* Call the  isp_ctx: acquire_hw_in_acquired.
* Now even though the allocated strructure version is v1, in
  acquire_hw_in_acquired call to api of version v2 would get invoked.
* Leading to OOB reads/writes.

CRs-Fixed: 4216838
Change-Id: I88d1c76438b56d6ccfa014aa440a536ac5bdd27a
Signed-off-by: Vivek Yadav <viveyada@qti.qualcomm.com>
(cherry picked from commit 55273537c3c23152bba518402a96a86918e3f56c)
This commit is contained in:
Vivek Yadav 2025-08-12 10:58:23 +05:30 • committed by Prateek Pallav
commit bca82b3563

View file

@ -812,6 +812,7 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd)
}
case CAM_ACQUIRE_HW: {
uint32_t api_version;
uint32_t struct_version;
void *acquire_ptr = NULL;
size_t acquire_size;
@ -846,6 +847,16 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd)
}
if (api_version == 1) {
struct_version =
((struct cam_acquire_hw_cmd_v1 *)acquire_ptr)->struct_version;
if (struct_version != api_version) {
CAM_ERR(CAM_CORE,
"Unmatched struct api version %u and struct version %u",
api_version, struct_version);
rc = -EINVAL;
goto acquire_free;
}
rc = __cam_node_handle_acquire_hw_v1(node, acquire_ptr);
if (rc) {
CAM_ERR(CAM_CORE,
@ -853,6 +864,16 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd)
goto acquire_kfree;
}
} else if (api_version == 2) {
struct_version =
((struct cam_acquire_hw_cmd_v2 *)acquire_ptr)->struct_version;
if (struct_version != api_version) {
CAM_ERR(CAM_CORE,
"Unmatched struct api version %u and struct version %u",
api_version, struct_version);
rc = -EINVAL;
goto acquire_free;
}
rc = __cam_node_handle_acquire_hw_v2(node, acquire_ptr);
if (rc) {
CAM_ERR(CAM_CORE,