mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 04:12:04 -04:00
msm: camera: isp: Fix potential illegal access in Acquire HW
Fix potential illegal acquire_hw memory access due to following scenario. Even though ioctl is synchronous, the kernel performs 1. copy_from_user(&api_version, ...) — reads just the version. 2. Allocates buffer based on version. 3. copy_from_user(acquire_ptr, ...) — reads the full structure. If another thread modifies the user-space buffer (cmd->handle) between steps 1 and 3, the kernel will * Allocate a buffer for version 1. * But read data formatted for version 1, by modifying api version v2. * Call the isp_ctx: acquire_hw_in_acquired. * Now even though the allocated strructure version is v1, in acquire_hw_in_acquired call to api of version v2 would get invoked. * Leading to OOB reads/writes. CRs-Fixed: 4216838 Change-Id: I88d1c76438b56d6ccfa014aa440a536ac5bdd27a Signed-off-by: Vivek Yadav <viveyada@qti.qualcomm.com> (cherry picked from commit 55273537c3c23152bba518402a96a86918e3f56c)
This commit is contained in:
parent
3b061e5b70
commit
bca82b3563
1 changed files with 21 additions and 0 deletions
|
|
@ -812,6 +812,7 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd)
|
|||
}
|
||||
case CAM_ACQUIRE_HW: {
|
||||
uint32_t api_version;
|
||||
uint32_t struct_version;
|
||||
void *acquire_ptr = NULL;
|
||||
size_t acquire_size;
|
||||
|
||||
|
|
@ -846,6 +847,16 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd)
|
|||
}
|
||||
|
||||
if (api_version == 1) {
|
||||
struct_version =
|
||||
((struct cam_acquire_hw_cmd_v1 *)acquire_ptr)->struct_version;
|
||||
if (struct_version != api_version) {
|
||||
CAM_ERR(CAM_CORE,
|
||||
"Unmatched struct api version %u and struct version %u",
|
||||
api_version, struct_version);
|
||||
rc = -EINVAL;
|
||||
goto acquire_free;
|
||||
}
|
||||
|
||||
rc = __cam_node_handle_acquire_hw_v1(node, acquire_ptr);
|
||||
if (rc) {
|
||||
CAM_ERR(CAM_CORE,
|
||||
|
|
@ -853,6 +864,16 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd)
|
|||
goto acquire_kfree;
|
||||
}
|
||||
} else if (api_version == 2) {
|
||||
struct_version =
|
||||
((struct cam_acquire_hw_cmd_v2 *)acquire_ptr)->struct_version;
|
||||
if (struct_version != api_version) {
|
||||
CAM_ERR(CAM_CORE,
|
||||
"Unmatched struct api version %u and struct version %u",
|
||||
api_version, struct_version);
|
||||
rc = -EINVAL;
|
||||
goto acquire_free;
|
||||
}
|
||||
|
||||
rc = __cam_node_handle_acquire_hw_v2(node, acquire_ptr);
|
||||
if (rc) {
|
||||
CAM_ERR(CAM_CORE,
|
||||
|
|
|
|||
Loading…
Reference in a new issue