diff --git a/techpack/audio/asoc/msm-compress-q6-v2.c b/techpack/audio/asoc/msm-compress-q6-v2.c index ce177a4b990f..14f549310547 100644 --- a/techpack/audio/asoc/msm-compress-q6-v2.c +++ b/techpack/audio/asoc/msm-compress-q6-v2.c @@ -4143,7 +4143,7 @@ static int msm_compr_channel_map_put(struct snd_kcontrol *kcontrol, pr_debug("%s: fe_id- %llu\n", __func__, fe_id); - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s Received out of bounds fe_id %llu\n", __func__, fe_id); rc = -EINVAL; @@ -4185,7 +4185,7 @@ static int msm_compr_channel_map_get(struct snd_kcontrol *kcontrol, int rc = 0, i; pr_debug("%s: fe_id- %llu\n", __func__, fe_id); - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: Received out of bounds fe_id %llu\n", __func__, fe_id); rc = -EINVAL; diff --git a/techpack/audio/asoc/msm-pcm-routing-v2.c b/techpack/audio/asoc/msm-pcm-routing-v2.c index 0e05f6f1545f..7c0051617ea8 100644 --- a/techpack/audio/asoc/msm-pcm-routing-v2.c +++ b/techpack/audio/asoc/msm-pcm-routing-v2.c @@ -3,6 +3,7 @@ * * Changes from Qualcomm Innovation Center are provided under the following license: * Copyright (c) 2022-2023 Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted (subject to the limitations in the @@ -2308,7 +2309,7 @@ static int msm_pcm_routing_channel_mixer_v2(int fe_id, bool perf_mode, int i = 0, j = 0, be_id = 0; int ret = 0; - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: invalid FE %d\n", __func__, fe_id); return 0; } @@ -2376,7 +2377,7 @@ static int msm_pcm_routing_channel_mixer(int fe_id, bool perf_mode, return ret; } - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: invalid FE %d\n", __func__, fe_id); return 0; } diff --git a/techpack/audio/asoc/msm-qti-pp-config.c b/techpack/audio/asoc/msm-qti-pp-config.c index cdc0f38168f5..5bac60210bf0 100644 --- a/techpack/audio/asoc/msm-qti-pp-config.c +++ b/techpack/audio/asoc/msm-qti-pp-config.c @@ -1,5 +1,6 @@ // SPDX-License-Identifier: GPL-2.0-only /* Copyright (c) 2012-2021, The Linux Foundation. All rights reserved. + * Copyright (c) 2024 Qualcomm Innovation Center, Inc. All rights reserved. */ #include @@ -178,7 +179,7 @@ static int msm_qti_pp_put_dtmf_module_enable fe_id = ((struct soc_multi_mixer_control *) kcontrol->private_value)->shift; - if (fe_id >= MSM_FRONTEND_DAI_MM_SIZE) { + if (fe_id >= MSM_FRONTEND_DAI_MAX) { pr_err("%s: invalid FE %d\n", __func__, fe_id); return -EINVAL; } diff --git a/techpack/audio/dsp/q6voice.c b/techpack/audio/dsp/q6voice.c index 769fb9ff41a3..23bc780a6932 100644 --- a/techpack/audio/dsp/q6voice.c +++ b/techpack/audio/dsp/q6voice.c @@ -1,7 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2012-2021, The Linux Foundation. All rights reserved. - * Copyright (c) 2022-2023, Qualcomm Innovation Center, Inc. All rights reserved. + * Copyright (c) 2022-2024, Qualcomm Innovation Center, Inc. All rights reserved. */ #include #include @@ -8093,7 +8093,7 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv) VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_READY) { int ret = 0; u16 cvs_handle; - uint32_t *cvs_voc_pkt; + uint32_t *cvs_voc_pkt, tot_buf_sz; struct cvs_enc_buffer_consumed_cmd send_enc_buf_consumed_cmd; void *apr_cvs; @@ -8122,9 +8122,14 @@ static int32_t qdsp_cvs_callback(struct apr_client_data *data, void *priv) VSS_ISTREAM_EVT_OOB_NOTIFY_ENC_BUFFER_CONSUMED; cvs_voc_pkt = v->shmem_info.sh_buf.buf[1].data; + + if (__builtin_add_overflow(cvs_voc_pkt[2], 3 * sizeof(uint32_t), &tot_buf_sz)) { + pr_err("%s: integer overflow detected\n", __func__); + return -EINVAL; + } + if (cvs_voc_pkt != NULL && common.mvs_info.ul_cb != NULL) { - if (v->shmem_info.sh_buf.buf[1].size < - ((3 * sizeof(uint32_t)) + cvs_voc_pkt[2])) { + if (v->shmem_info.sh_buf.buf[1].size < tot_buf_sz) { pr_err("%s: invalid voc pkt size\n", __func__); return -EINVAL; }