Merge tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina

"LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0"

* tag 'LA.UM.9.14.1.r1-14100-QCM6490.QSSI14.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
  asoc: Fix out-of-bound write
  dsp: q6voice: Adds checks for an integer overflow
  dsp: q6voice: Adds checks for an integer overflow

Change-Id: Ieb4b3e8ead0616624b7492cfc42bb72a024525b7
This commit is contained in:
Michael Bestas 2024-06-22 17:49:19 +03:00
commit ff12c3d353
No known key found for this signature in database
GPG key ID: CC95044519BE6669
4 changed files with 16 additions and 9 deletions

View file

@ -4143,7 +4143,7 @@ static int msm_compr_channel_map_put(struct snd_kcontrol *kcontrol,
pr_debug("%s: fe_id- %llu\n", __func__, fe_id);
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
pr_err("%s Received out of bounds fe_id %llu\n",
__func__, fe_id);
rc = -EINVAL;
@ -4185,7 +4185,7 @@ static int msm_compr_channel_map_get(struct snd_kcontrol *kcontrol,
int rc = 0, i;
pr_debug("%s: fe_id- %llu\n", __func__, fe_id);
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
pr_err("%s: Received out of bounds fe_id %llu\n",
__func__, fe_id);
rc = -EINVAL;

View file

@ -3,6 +3,7 @@
*
* Changes from Qualcomm Innovation Center are provided under the following license:
* Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved.
*
* Redistribution and use in source and binary forms, with or without
* modification, are permitted (subject to the limitations in the
@ -2308,7 +2309,7 @@ static int msm_pcm_routing_channel_mixer_v2(int fe_id, bool perf_mode,
int i = 0, j = 0, be_id = 0;
int ret = 0;
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
pr_err("%s: invalid FE %d\n", __func__, fe_id);
return 0;
}
@ -2376,7 +2377,7 @@ static int msm_pcm_routing_channel_mixer(int fe_id, bool perf_mode,
return ret;
}
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
pr_err("%s: invalid FE %d\n", __func__, fe_id);
return 0;
}

View file

@ -1,5 +1,6 @@
// SPDX-License-Identifier: GPL-2.0-only
/* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved.
* Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/err.h>
@ -178,7 +179,7 @@ static int msm_qti_pp_put_dtmf_module_enable
fe_id = ((struct soc_multi_mixer_control *)
kcontrol->private_value)->shift;
if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) {
if (fe_id >= MSM_FRONTEND_DAI_MAX) {
pr_err("%s: invalid FE %d\n", __func__, fe_id);
return -EINVAL;
}

View file

@ -1,7 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved.
* Copyright (c) 2022-2023, Qualcomm Innovation Center, Inc. All rights reserved.
* Copyright (c) 2022-2024, Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/slab.h>
#include <linux/kthread.h>
@ -8093,7 +8093,7 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv)
VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_READY) {
int ret = 0;
u16 cvs_handle;
uint32_t *cvs_voc_pkt;
uint32_t *cvs_voc_pkt, tot_buf_sz;
struct cvs_enc_buffer_consumed_cmd send_enc_buf_consumed_cmd;
void *apr_cvs;
@ -8122,9 +8122,14 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv)
VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_CONSUMED;
cvs_voc_pkt = v->shmem_info.sh_buf.buf[1].data;
if (__builtin_add_overflow(cvs_voc_pkt[2], 3 * sizeof(uint32_t), &tot_buf_sz)) {
pr_err("%s: integer overflow detected\n", __func__);
return -EINVAL;
}
if (cvs_voc_pkt != NULL && common.mvs_info.ul_cb != NULL) {
if (v->shmem_info.sh_buf.buf[1].size <
((3 * sizeof(uint32_t)) + cvs_voc_pkt[2])) {
if (v->shmem_info.sh_buf.buf[1].size < tot_buf_sz) {
pr_err("%s: invalid voc pkt size\n", __func__);
return -EINVAL;
}