asoc: check param_size before use it in memcpy

If param_size is not the correct size when it's
passed to memcpy, it could result wrong parameter
to be sent to ADSP by audio driver.

Change-Id: Iaf66a87c405bd0508bb0771c5fe20626f2b75dda
Signed-off-by: Xiaoyu Ye <benyxy@codeaurora.org>
This commit is contained in:
Xiaoyu Ye 2020-06-29 04:16:17 -07:00
commit e1e34edd16

View file

@ -881,8 +881,16 @@ static int msm_lsm_dereg_model(struct snd_pcm_substream *substream,
}
if (sm->model_id == p_info->model_id) {
rc = q6lsm_set_one_param(client, p_info, NULL,
LSM_DEREG_MULTI_SND_MODEL);
if (p_info->param_size != sizeof(p_info->model_id)) {
rc = -EINVAL;
pr_err("%s: %s failed, p_info->param_size is invalid: %d\n",
__func__, "LSM_DEREG_MULTI_SND_MODEL",
p_info->param_size);
} else {
rc = q6lsm_set_one_param(client, p_info, NULL,
LSM_DEREG_MULTI_SND_MODEL);
}
if (rc)
dev_err(rtd->dev,
"%s: Failed to deregister snd_model %d, err = %d\n",