usb: gadget: Avoid NULL pointer dereference during OS descriptors handling

With multi-config compositions some hosts can bind the configuration
incorrectly and sending os descriptor request on invalid interface.
This could cause accessing NULL pointer and results in panic.

Fix this by bailing out from the OS descriptor setup request handling
if the interface is NULL.

Change-Id: I65f01b876a46b907eb883e48878fc081860b0753
Signed-off-by: Chandana Kishori Chiluveru <cchiluve@codeaurora.org>
This commit is contained in:
Chandana Kishori Chiluveru 2018-09-10 19:27:36 +05:30 • committed by Gerrit - the friendly Code Review server
commit cd8dbdaeb5

View file

@ -1577,6 +1577,9 @@ static int count_ext_prop(struct usb_configuration *c, int interface)
struct usb_function *f;
int j;
if (interface >= c->next_interface_id)
return -EINVAL;
f = c->interface[interface];
for (j = 0; j < f->os_desc_n; ++j) {
struct usb_os_desc *d;
@ -1596,6 +1599,9 @@ static int len_ext_prop(struct usb_configuration *c, int interface)
struct usb_os_desc *d;
int j, res;
if (interface >= c->next_interface_id)
return -EINVAL;
res = 10; /* header length */
f = c->interface[interface];
for (j = 0; j < f->os_desc_n; ++j) {
@ -1976,6 +1982,8 @@ unknown:
buf[6] = w_index;
count = count_ext_prop(os_desc_cfg,
interface);
if (count < 0)
return count;
put_unaligned_le16(count, buf + 8);
count = len_ext_prop(os_desc_cfg,
interface);