mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-08 12:58:12 -04:00
Merge tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina
"LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0" * tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel: asoc: Fix out-of-bound write dsp: q6voice: Adds checks for an integer overflow dsp: q6voice: Adds checks for an integer overflow Change-Id: Ieb4b3e8ead0616624b7492cfc42bb72a024525b7
This commit is contained in:
commit
ff12c3d353
4 changed files with 16 additions and 9 deletions
|
|
@ -4143,7 +4143,7 @@ static int msm_compr_channel_map_put(struct snd_kcontrol *kcontrol,
|
|||
|
||||
pr_debug("%s: fe_id- %llu\n", __func__, fe_id);
|
||||
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
|
||||
pr_err("%s Received out of bounds fe_id %llu\n",
|
||||
__func__, fe_id);
|
||||
rc = -EINVAL;
|
||||
|
|
@ -4185,7 +4185,7 @@ static int msm_compr_channel_map_get(struct snd_kcontrol *kcontrol,
|
|||
int rc = 0, i;
|
||||
|
||||
pr_debug("%s: fe_id- %llu\n", __func__, fe_id);
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
|
||||
pr_err("%s: Received out of bounds fe_id %llu\n",
|
||||
__func__, fe_id);
|
||||
rc = -EINVAL;
|
||||
|
|
|
|||
|
|
@ -3,6 +3,7 @@
|
|||
*
|
||||
* Changes from Qualcomm Innovation Center are provided under the following license:
|
||||
* Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*
|
||||
* Redistribution and use in source and binary forms, with or without
|
||||
* modification, are permitted (subject to the limitations in the
|
||||
|
|
@ -2308,7 +2309,7 @@ static int msm_pcm_routing_channel_mixer_v2(int fe_id, bool perf_mode,
|
|||
int i = 0, j = 0, be_id = 0;
|
||||
int ret = 0;
|
||||
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
|
||||
pr_err("%s: invalid FE %d\n", __func__, fe_id);
|
||||
return 0;
|
||||
}
|
||||
|
|
@ -2376,7 +2377,7 @@ static int msm_pcm_routing_channel_mixer(int fe_id, bool perf_mode,
|
|||
return ret;
|
||||
}
|
||||
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
|
||||
pr_err("%s: invalid FE %d\n", __func__, fe_id);
|
||||
return 0;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1,5 +1,6 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/err.h>
|
||||
|
|
@ -178,7 +179,7 @@ static int msm_qti_pp_put_dtmf_module_enable
|
|||
|
||||
fe_id = ((struct soc_multi_mixer_control *)
|
||||
kcontrol->private_value)->shift;
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
|
||||
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
|
||||
pr_err("%s: invalid FE %d\n", __func__, fe_id);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022-2023, Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
* Copyright (c) 2022-2024, Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
#include <linux/slab.h>
|
||||
#include <linux/kthread.h>
|
||||
|
|
@ -8093,7 +8093,7 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv)
|
|||
VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_READY) {
|
||||
int ret = 0;
|
||||
u16 cvs_handle;
|
||||
uint32_t *cvs_voc_pkt;
|
||||
uint32_t *cvs_voc_pkt, tot_buf_sz;
|
||||
struct cvs_enc_buffer_consumed_cmd send_enc_buf_consumed_cmd;
|
||||
void *apr_cvs;
|
||||
|
||||
|
|
@ -8122,9 +8122,14 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv)
|
|||
VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_CONSUMED;
|
||||
|
||||
cvs_voc_pkt = v->shmem_info.sh_buf.buf[1].data;
|
||||
|
||||
if (__builtin_add_overflow(cvs_voc_pkt[2], 3 * sizeof(uint32_t), &tot_buf_sz)) {
|
||||
pr_err("%s: integer overflow detected\n", __func__);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (cvs_voc_pkt != NULL && common.mvs_info.ul_cb != NULL) {
|
||||
if (v->shmem_info.sh_buf.buf[1].size <
|
||||
((3 * sizeof(uint32_t)) + cvs_voc_pkt[2])) {
|
||||
if (v->shmem_info.sh_buf.buf[1].size < tot_buf_sz) {
|
||||
pr_err("%s: invalid voc pkt size\n", __func__);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue