crypto: msm: restrict value of num_fds to QCEDEV_MAX_BUFFERS

Set the max value of num_fds to QCEDEV_MAX_BUFFERS to prevent
out of bound access of fd, fd_size, fd_offset array.

Change-Id: I88889472a4bd14f786588bd2c9e06e69a98e94c9
Signed-off-by: Prerna Kalla <prernak@codeaurora.org>
This commit is contained in:
Prerna Kalla 2020-03-30 17:31:07 +05:30 • committed by Gerrit - the friendly Code Review server
commit c95de1aead

View file

@ -1925,6 +1925,11 @@ long qcedev_ioctl(struct file *file,
goto exit_free_qcedev_areq;
}
if (map_buf.num_fds > QCEDEV_MAX_BUFFERS) {
err = -EINVAL;
goto exit_free_qcedev_areq;
}
for (i = 0; i < map_buf.num_fds; i++) {
err = qcedev_check_and_map_buffer(handle,
map_buf.fd[i],