mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 20:33:58 -04:00
soc: qcom: spcom: Pass channel name as formatted string to device_create
Pass channel name as formmated string to device_create call in spcom_create_channel_chardevto prevent memory access issues when using formatted string as channel name. Change-Id: I549087a49e97f0b1a66ea5816eabfe80a6f7f1f7 Signed-off-by: Liron Daniel <lirond@codeaurora.org>
This commit is contained in:
parent
62da00618b
commit
cfa75093c0
1 changed files with 12 additions and 7 deletions
|
|
@ -621,7 +621,6 @@ static int spcom_handle_create_channel_command(void *cmd_buf, int cmd_size)
|
|||
{
|
||||
int ret = 0;
|
||||
struct spcom_user_create_channel_command *cmd = cmd_buf;
|
||||
const size_t maxlen = sizeof(cmd->ch_name);
|
||||
|
||||
if (cmd_size != sizeof(*cmd)) {
|
||||
spcom_pr_err("cmd_size [%d] , expected [%d]\n",
|
||||
|
|
@ -629,11 +628,6 @@ static int spcom_handle_create_channel_command(void *cmd_buf, int cmd_size)
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (strnlen(cmd->ch_name, maxlen) == maxlen) {
|
||||
spcom_pr_err("channel name is not NULL terminated\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
mutex_lock(&spcom_dev->chdev_count_lock);
|
||||
ret = spcom_create_channel_chardev(cmd->ch_name, cmd->is_sharable);
|
||||
mutex_unlock(&spcom_dev->chdev_count_lock);
|
||||
|
|
@ -2003,6 +1997,12 @@ static int spcom_create_channel_chardev(const char *name, bool is_sharable)
|
|||
void *priv;
|
||||
struct cdev *cdev;
|
||||
|
||||
if (!name || strnlen(name, SPCOM_CHANNEL_NAME_SIZE) ==
|
||||
SPCOM_CHANNEL_NAME_SIZE) {
|
||||
spcom_pr_err("invalid channel name\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
spcom_pr_dbg("creating channel [%s]\n", name);
|
||||
|
||||
ch = spcom_find_channel_by_name(name);
|
||||
|
|
@ -2037,7 +2037,12 @@ static int spcom_create_channel_chardev(const char *name, bool is_sharable)
|
|||
|
||||
devt = spcom_dev->device_no + spcom_dev->chdev_count;
|
||||
priv = ch;
|
||||
dev = device_create(cls, parent, devt, priv, name);
|
||||
|
||||
/*
|
||||
* Pass channel name as formatted string to avoid abuse by using a
|
||||
* formatted string as channel name
|
||||
*/
|
||||
dev = device_create(cls, parent, devt, priv, "%s", name);
|
||||
if (IS_ERR(dev)) {
|
||||
spcom_pr_err("device_create failed\n");
|
||||
ret = -ENODEV;
|
||||
|
|
|
|||
Loading…
Reference in a new issue