Merge tag 'LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina

"LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0"

* tag 'LA.UM.9.14.r1-25000.02-LAHAINA.QSSI14.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
  msm-5.4.c3: qseecom: Fix possible race condition
  msm: adsprpc: Avoid taking reference for group_info
  adsprpc: Handle UAF scenario in put_args
  msm-5.4.c3: qseecom: Fix possible race condition
  USB: storage: Replace the sprintf with scnprintf
  adsprpc: Handle UAF scenario in put_args
  msm: adsprpc: Avoid taking reference for group_info
  usb: gadget: f_gsi: bail out if opts is null
  msm: ep_pcie: Avoid setting host wake pending flag for D0
  msm: ep_pcie: Prevent repetitive wake operation if wake is in process
  msm_ipa: Install exception rule for PPPoE-MPLS
  securemsm-kernel: Decrement the server object ref count in mutex context
  qcedev: fix UAF in qcedev_smmu
  thermal: qcom: Add support to update tsens trip based on nvmem data
  msm: eva: Fix UAF issue when remove module
  msm: cvp: OOB write fix due to integer underflow
  msm: ep_pcie: Avoid writing req_L1_exit during dstate change
  msm: eva: Adding kref count for cvp_get_inst_from_id

Change-Id: I3dad70dec062688b50554d7676a4b85bcb42fad9
This commit is contained in:
Michael Bestas 2024-10-01 11:13:13 +03:00 • committed by Alexander Winkowski
commit defbd8dccd
No known key found for this signature in database
GPG key ID: 72762A66704CDE44
14 changed files with 45183 additions and 44839 deletions

View file

@ -1,7 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2016-2021, The Linux Foundation. All rights reserved.
* Copyright (c) 2022 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) 2022, 2024 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#define pr_fmt(fmt) "smcinvoke: %s: " fmt, __func__
@ -1866,8 +1866,11 @@ static long process_accept_req(struct file *filp, unsigned int cmd,
}
} while (!cb_txn);
out:
if (server_info)
if (server_info) {
mutex_lock(&g_smcinvoke_lock);
kref_put(&server_info->ref_cnt, destroy_cb_server);
mutex_unlock(&g_smcinvoke_lock);
}
if (ret && ret != -ERESTARTSYS)
pr_err("accept thread returning with ret: %d\n", ret);