From 013c2977473bda1c24bc959c34bf686f9c68b5e9 Mon Sep 17 00:00:00 2001 From: Jeya R Date: Thu, 25 Feb 2021 16:24:16 +0530 Subject: [PATCH] msm: adsprpc: Do length check to avoid arbitrary memory access Do length check while mapping ion buffers to avoid arbitrary physical memory read on DSP which can lead to DOS. Change-Id: I6334d4ceac795595aa3dc4bc71e6c736d2461c51 Acked-by: Deepika Singh Signed-off-by: Jeya R --- drivers/char/adsprpc.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c index e0404a3bd918..179be6df613a 100644 --- a/drivers/char/adsprpc.c +++ b/drivers/char/adsprpc.c @@ -2397,7 +2397,7 @@ static int get_args(uint32_t kernel, struct smq_invoke_ctx *ctx) } offset = buf_page_start(buf) - vma->vm_start; up_read(¤t->mm->mmap_sem); - VERIFY(err, offset < (uintptr_t)map->size); + VERIFY(err, offset + len <= (uintptr_t)map->size); if (err) { ADSPRPC_ERR( "buffer address is invalid for the fd passed for %d address 0x%llx and size %zu\n",