From cfe6d558b261d799bffa7ffc56a232ee5cec6b68 Mon Sep 17 00:00:00 2001 From: Ashok Vuyyuru Date: Wed, 20 Oct 2021 01:13:15 +0530 Subject: [PATCH] msm: ipa3: Fix to NULL terminate the header pointer in proc header table While resetting the header rules if it find invalid header ID it will return before freeting proc header table it was leading to use after free when accessing the header pointer from proc header table. Adding changes to NULL terminating header pointer in proc header table after header table deleted from the list. Change-Id: If270d855d3907e61368336316161a250053e1e62 Signed-off-by: Ashok Vuyyuru --- drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c b/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c index 96d783245e39..1183d8e275c0 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c @@ -1084,6 +1084,7 @@ int ipa3_reset_hdr(bool user_only) if (ipa3_id_find(entry->id) == NULL) { mutex_unlock(&ipa3_ctx->lock); + IPAERR_RL("Invalid header ID\n"); WARN_ON_RATELIMIT_IPA(1); return -EFAULT; } @@ -1094,6 +1095,7 @@ int ipa3_reset_hdr(bool user_only) entry->phys_base, entry->hdr_len, DMA_TO_DEVICE); + entry->proc_ctx->hdr = NULL; entry->proc_ctx = NULL; } else { /* move the offset entry to free list */ @@ -1151,6 +1153,7 @@ int ipa3_reset_hdr(bool user_only) if (ipa3_id_find(ctx_entry->id) == NULL) { mutex_unlock(&ipa3_ctx->lock); + IPAERR_RL("Invalid proc header ID\n"); WARN_ON_RATELIMIT_IPA(1); return -EFAULT; }