mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 13:49:24 -04:00
usb: gadget: Avoid NULL pointer dereference during OS descriptors handling
With multi-config compositions some hosts can bind the configuration incorrectly and sending os descriptor request on invalid interface. This could cause accessing NULL pointer and results in panic. Fix this by bailing out from the OS descriptor setup request handling if the interface is NULL. Change-Id: I65f01b876a46b907eb883e48878fc081860b0753 Signed-off-by: Chandana Kishori Chiluveru <cchiluve@codeaurora.org>
This commit is contained in:
parent
f838988d41
commit
cd8dbdaeb5
1 changed files with 8 additions and 0 deletions
|
|
@ -1577,6 +1577,9 @@ static int count_ext_prop(struct usb_configuration *c, int interface)
|
|||
struct usb_function *f;
|
||||
int j;
|
||||
|
||||
if (interface >= c->next_interface_id)
|
||||
return -EINVAL;
|
||||
|
||||
f = c->interface[interface];
|
||||
for (j = 0; j < f->os_desc_n; ++j) {
|
||||
struct usb_os_desc *d;
|
||||
|
|
@ -1596,6 +1599,9 @@ static int len_ext_prop(struct usb_configuration *c, int interface)
|
|||
struct usb_os_desc *d;
|
||||
int j, res;
|
||||
|
||||
if (interface >= c->next_interface_id)
|
||||
return -EINVAL;
|
||||
|
||||
res = 10; /* header length */
|
||||
f = c->interface[interface];
|
||||
for (j = 0; j < f->os_desc_n; ++j) {
|
||||
|
|
@ -1976,6 +1982,8 @@ unknown:
|
|||
buf[6] = w_index;
|
||||
count = count_ext_prop(os_desc_cfg,
|
||||
interface);
|
||||
if (count < 0)
|
||||
return count;
|
||||
put_unaligned_le16(count, buf + 8);
|
||||
count = len_ext_prop(os_desc_cfg,
|
||||
interface);
|
||||
|
|
|
|||
Loading…
Reference in a new issue