mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-09 21:59:12 -04:00
msm: cvp: OOB write fix due to integer underflow
If FW send a pkt->size which is less than the sizeof packet structure
then pkt->size - sizeof() would result into an integer underflow.
Due to this the subsequent check would be bypassed and we will
start write to an OOB memory.
Change-Id: Icb3e4e6d64275592ceb6f747de653dcc1c65fec7
Signed-off-by: ptak <quic_ptak@quicinc.com>
(cherry picked from commit 143f500168)
This commit is contained in:
parent
7798d6e33c
commit
d17869edb9
1 changed files with 2 additions and 1 deletions
|
|
@ -1,6 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2018-2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022-2024, Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/bitops.h>
|
||||
|
|
@ -559,7 +560,7 @@ static void hfi_process_sys_get_prop_image_version(
|
|||
int req_bytes;
|
||||
|
||||
req_bytes = pkt->size - sizeof(*pkt);
|
||||
if (req_bytes < version_string_size ||
|
||||
if (req_bytes < (signed int)version_string_size ||
|
||||
!pkt->rg_property_data[1] ||
|
||||
pkt->num_properties > 1) {
|
||||
dprintk(CVP_ERR, "%s: bad_pkt: %d\n", __func__, req_bytes);
|
||||
|
|
|
|||
Loading…
Reference in a new issue