mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-10 22:40:54 -04:00
rpmsg: slatecom: Discard unaligned packet to read
If intent_alloc_size and chunk size are unaligned with the minimum offset, then ahb_read can lead to bytes overflow as ahb_read is performed with word_size aligned. If the received chunk_size is not aligned to word_size, discard packet to read. Change-Id: I36fabc8bde22355de1ae32cb026a2a246778d47e Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
This commit is contained in:
parent
8b685a05b5
commit
c670d30054
1 changed files with 9 additions and 0 deletions
|
|
@ -1694,12 +1694,21 @@ static int glink_slatecom_rx_data(struct glink_slatecom *glink,
|
|||
|
||||
if (intent->size - intent->offset < chunk_size) {
|
||||
dev_err(glink->dev, "Insufficient space in intent\n");
|
||||
glink_slatecom_free_intent(channel, intent);
|
||||
mutex_unlock(&channel->intent_lock);
|
||||
|
||||
/* The packet header lied, drop payload */
|
||||
return msglen;
|
||||
}
|
||||
|
||||
if (chunk_size % WORD_SIZE) {
|
||||
dev_err(glink->dev, "For chunk_size %d use short packet\n",
|
||||
chunk_size);
|
||||
glink_slatecom_free_intent(channel, intent);
|
||||
mutex_unlock(&channel->intent_lock);
|
||||
return msglen;
|
||||
}
|
||||
|
||||
rc = slatecom_ahb_read(glink->slatecom_handle, (uint32_t)(size_t)addr,
|
||||
ALIGN(chunk_size, WORD_SIZE)/WORD_SIZE,
|
||||
intent->data + intent->offset);
|
||||
|
|
|
|||
Loading…
Reference in a new issue