From d2796402258b70afe2bf3200bf9105e8f421d38f Mon Sep 17 00:00:00 2001 From: Manu Gautam Date: Wed, 20 May 2020 15:47:31 +0530 Subject: [PATCH] mhi: core: Add checks for bhi and bhie offsets Bail out if device returns invalid bhi/bhie offsets. Change-Id: Ifc92c53a4c1f7c951721cbec0b1d7285cf19cd72 Signed-off-by: Manu Gautam --- drivers/bus/mhi/core/mhi_pm.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/drivers/bus/mhi/core/mhi_pm.c b/drivers/bus/mhi/core/mhi_pm.c index 61477d823742..c0017336b2a2 100644 --- a/drivers/bus/mhi/core/mhi_pm.c +++ b/drivers/bus/mhi/core/mhi_pm.c @@ -968,6 +968,13 @@ int mhi_async_power_up(struct mhi_controller *mhi_cntrl) goto error_bhi_offset; } + if (val >= mhi_cntrl->len) { + ret = -ENODEV; + write_unlock_irq(&mhi_cntrl->pm_lock); + MHI_ERR("Invalid bhi offset:%x\n", val); + goto error_bhi_offset; + } + mhi_cntrl->bhi = mhi_cntrl->regs + val; /* setup bhie offset if not set */ @@ -979,6 +986,13 @@ int mhi_async_power_up(struct mhi_controller *mhi_cntrl) goto error_bhi_offset; } + if (val >= mhi_cntrl->len) { + ret = -ENODEV; + write_unlock_irq(&mhi_cntrl->pm_lock); + MHI_ERR("Invalid bhie offset:%x\n", val); + goto error_bhi_offset; + } + mhi_cntrl->bhie = mhi_cntrl->regs + val; }