From bca82b35630747e34cbf2a8f830d5ce6216f176c Mon Sep 17 00:00:00 2001 From: Vivek Yadav Date: Tue, 12 Aug 2025 10:58:23 +0530 Subject: [PATCH] msm: camera: isp: Fix potential illegal access in Acquire HW MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Fix potential illegal acquire_hw memory access due to following scenario. Even though ioctl is synchronous, the kernel performs 1. copy_from_user(&api_version, ...) — reads just the version. 2. Allocates buffer based on version. 3. copy_from_user(acquire_ptr, ...) — reads the full structure. If another thread modifies the user-space buffer (cmd->handle) between steps 1 and 3, the kernel will * Allocate a buffer for version 1. * But read data formatted for version 1, by modifying api version v2. * Call the isp_ctx: acquire_hw_in_acquired. * Now even though the allocated strructure version is v1, in acquire_hw_in_acquired call to api of version v2 would get invoked. * Leading to OOB reads/writes. CRs-Fixed: 4216838 Change-Id: I88d1c76438b56d6ccfa014aa440a536ac5bdd27a Signed-off-by: Vivek Yadav (cherry picked from commit 55273537c3c23152bba518402a96a86918e3f56c) --- drivers/cam_core/cam_node.c | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) diff --git a/drivers/cam_core/cam_node.c b/drivers/cam_core/cam_node.c index d27bcdd6bf0d..4561aecb6f7e 100644 --- a/drivers/cam_core/cam_node.c +++ b/drivers/cam_core/cam_node.c @@ -812,6 +812,7 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd) } case CAM_ACQUIRE_HW: { uint32_t api_version; + uint32_t struct_version; void *acquire_ptr = NULL; size_t acquire_size; @@ -846,6 +847,16 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd) } if (api_version == 1) { + struct_version = + ((struct cam_acquire_hw_cmd_v1 *)acquire_ptr)->struct_version; + if (struct_version != api_version) { + CAM_ERR(CAM_CORE, + "Unmatched struct api version %u and struct version %u", + api_version, struct_version); + rc = -EINVAL; + goto acquire_free; + } + rc = __cam_node_handle_acquire_hw_v1(node, acquire_ptr); if (rc) { CAM_ERR(CAM_CORE, @@ -853,6 +864,16 @@ int cam_node_handle_ioctl(struct cam_node *node, struct cam_control *cmd) goto acquire_kfree; } } else if (api_version == 2) { + struct_version = + ((struct cam_acquire_hw_cmd_v2 *)acquire_ptr)->struct_version; + if (struct_version != api_version) { + CAM_ERR(CAM_CORE, + "Unmatched struct api version %u and struct version %u", + api_version, struct_version); + rc = -EINVAL; + goto acquire_free; + } + rc = __cam_node_handle_acquire_hw_v2(node, acquire_ptr); if (rc) { CAM_ERR(CAM_CORE,