From cfa75093c007e04daecd6de59f70ea032185ab50 Mon Sep 17 00:00:00 2001 From: Liron Daniel Date: Wed, 22 Apr 2020 00:26:37 +0300 Subject: [PATCH] soc: qcom: spcom: Pass channel name as formatted string to device_create Pass channel name as formmated string to device_create call in spcom_create_channel_chardevto prevent memory access issues when using formatted string as channel name. Change-Id: I549087a49e97f0b1a66ea5816eabfe80a6f7f1f7 Signed-off-by: Liron Daniel --- drivers/soc/qcom/spcom.c | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/drivers/soc/qcom/spcom.c b/drivers/soc/qcom/spcom.c index 1016843ca039..a966ba98c30a 100644 --- a/drivers/soc/qcom/spcom.c +++ b/drivers/soc/qcom/spcom.c @@ -621,7 +621,6 @@ static int spcom_handle_create_channel_command(void *cmd_buf, int cmd_size) { int ret = 0; struct spcom_user_create_channel_command *cmd = cmd_buf; - const size_t maxlen = sizeof(cmd->ch_name); if (cmd_size != sizeof(*cmd)) { spcom_pr_err("cmd_size [%d] , expected [%d]\n", @@ -629,11 +628,6 @@ static int spcom_handle_create_channel_command(void *cmd_buf, int cmd_size) return -EINVAL; } - if (strnlen(cmd->ch_name, maxlen) == maxlen) { - spcom_pr_err("channel name is not NULL terminated\n"); - return -EINVAL; - } - mutex_lock(&spcom_dev->chdev_count_lock); ret = spcom_create_channel_chardev(cmd->ch_name, cmd->is_sharable); mutex_unlock(&spcom_dev->chdev_count_lock); @@ -2003,6 +1997,12 @@ static int spcom_create_channel_chardev(const char *name, bool is_sharable) void *priv; struct cdev *cdev; + if (!name || strnlen(name, SPCOM_CHANNEL_NAME_SIZE) == + SPCOM_CHANNEL_NAME_SIZE) { + spcom_pr_err("invalid channel name\n"); + return -EINVAL; + } + spcom_pr_dbg("creating channel [%s]\n", name); ch = spcom_find_channel_by_name(name); @@ -2037,7 +2037,12 @@ static int spcom_create_channel_chardev(const char *name, bool is_sharable) devt = spcom_dev->device_no + spcom_dev->chdev_count; priv = ch; - dev = device_create(cls, parent, devt, priv, name); + + /* + * Pass channel name as formatted string to avoid abuse by using a + * formatted string as channel name + */ + dev = device_create(cls, parent, devt, priv, "%s", name); if (IS_ERR(dev)) { spcom_pr_err("device_create failed\n"); ret = -ENODEV;