From 4856f7a40a673e60987482c62492946e48445e36 Mon Sep 17 00:00:00 2001 From: Tejas Prajapati Date: Mon, 20 Dec 2021 14:44:36 +0530 Subject: [PATCH] msm: camera: reqmgr: check if link handle is correctly passed Instead of the link handle if the dev handle is passed for dumping the request information, this can lead to accessing invalid data structure. To avodi accessing invalid data structure based on the dev handle, first check if the link handle passed in IOCTL is matchting with looked up link handle. CRs-Fixed: 3097336 Change-Id: I815457ff96e3b26fe9fa886bd984d53d209e4edb Signed-off-by: Tejas Prajapati --- drivers/cam_req_mgr/cam_req_mgr_core.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/cam_req_mgr/cam_req_mgr_core.c b/drivers/cam_req_mgr/cam_req_mgr_core.c index 05e6fdb90381..ac04553899a2 100644 --- a/drivers/cam_req_mgr/cam_req_mgr_core.c +++ b/drivers/cam_req_mgr/cam_req_mgr_core.c @@ -4542,7 +4542,7 @@ int cam_req_mgr_dump_request(struct cam_dump_req_cmd *dump_req) link = (struct cam_req_mgr_core_link *) cam_get_device_priv(dump_req->link_hdl); - if (!link) { + if (!link || link->link_hdl != dump_req->link_hdl) { CAM_DBG(CAM_CRM, "link ptr NULL %x", dump_req->link_hdl); rc = -EINVAL; goto end;