"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
msm: ipa3: reduce rx-wan pool and cmn page, temp pool sizes
msm: ipa: allocate page recycling buffers only once
msm: ipa: avoid OOM Killer for temp allocations
msm: ipa3: Flush free page WQ only for page recyle replenish handler
msm: ipa3: Fix to flush to workqueue during teardown pipe
msm: ipa3: Fix to destory workqueue only if created
msm: ipa3: Changes to enhance find free pages from list
msm: ipa: page pool recycling enhancements
msm: ipa: page pool recycling enhancements
Change-Id: I21c0f5974f08fc032605d2710858eb28e592d1f0
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
msm: camera: sensor: Proper handling of race condition in util api
msm: camera: sensor: Proper handling of race condition in util api
msm: camera: memmgr: Add missing calls of put buf to avoid leak
Change-Id: I0aff5a21e16f44c2e13ed99b463f326eb57b1653
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0:
Release 2.0.8.34M
qcacld-3.0: Add a sanity check to prevent integer overflow
Release 2.0.8.34L
qcacld-3.0: Fix possible spinlock acquire after destroy
Release 2.0.8.34K
qcacld-3.0: Find 6 GHz power type for connection channel
qcacld-3.0: Find best 6 GHz power type for connection
Release 2.0.8.34J
qcacld-3.0: Add vendor attribute for high RSSI roam trigger threshold
Change-Id: I740cd45f715d6609b53b19a9d42b0bf9df8983bc
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
qcacmn: Fix out of bound read issue in ESP ie parse
qcacmn: Update no. of DWORDs for htt_tx_msdu_desc_ext2_t
qcacmn: Change minimum mbssid ie length value to 1
qcacmn: Find 6 GHz power type for connection channel
qcacmn: Add an API to translate the 6 GHz channel enum
qcacmn: Find best 6 GHz power type for connection
qcacmn: Support 5 GHz high RSSI roam
qcacmn: Define QCA vendor attribute for high RSSI roam trigger threshold
Change-Id: Ie73b137390339317e5f3f4a72577b04d34c2f0c2
"LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0"
* tag 'LA.UM.9.14.r1-24200-LAHAINA.QSSI13.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
bus: mhi: Fix potential out-of-bound access
rpmsg: slatecom: maintain rx_size to read
rpmsg: slatecom: out of bound read from process_cmd
soc: qcom: add out of bound check for AON fifo
soc: qcom: smem: Add boundary checks for partitions
msm: kgsl: Do not release dma and anon buffers if unmap fails
msm: kgsl: Do not release dma and anon buffers if unmap fails
memshare: Prevent possible integer overflow
msm: kgsl: Keep the timeline fence valid for logging
msm: ipa: Add support for Private IP Forwarding
msm: ipa3: add support to identify wifi attach
soc: qcom: minidump_log: Protect md_dump_slabinfo under SLUB_DEBUG
mm: slub: Declare slab_owner_ops only when SLUB DEBUG is enabled
soc: qcom: Add BLAIR-LITE SoC information to socinfo
soc: qcom: socinfo: Add soc information for BLAIR LTE
msm_serial_hs: Fix race between mod_timer and del_timer calls
Change-Id: I5ab9a7732af0be4754b506f2c815ab29b236fb91
https://source.android.com/docs/security/bulletin/2024-03-01
* tag 'ASB-2024-03-05_11-5.4' of https://android.googlesource.com/kernel/common:
ANDROID: GKI: Update symbol list for Zebra
UPSTREAM: usb: raw-gadget: properly handle interrupted requests
UPSTREAM: net: prevent skb corruption on frag list segmentation
UPSTREAM: netfilter: nft_set_rbtree: skip end interval element from gc
UPSTREAM: net: tls, update curr on splice as well
Change-Id: I7a6117e861e8c35bb66bcc3a9a21cc6db49946b2
In mhi_sat_isvalid_header function if the length is less than
the size of header then there can be out-of-bound access.
So fix the len check in the function.
Change-Id: I80f1556557b1bf2f30c07f6377bd6e3db48712b3
Signed-off-by: Krishna chaitanya chundru <quic_krichai@quicinc.com>
(cherry picked from commit d7601393dc)
For cmd close_ack or open request where rx_size is being
incrementing with respect to offset might lead to out of
bound read from rx_data.
Decrease rx_size as we process commands.
Change-Id: I492eadcbebb78386fc20f744eb9ad8db4a2914fc
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit ab0f86134f)
When dereferencing "rx_data" as type "glink_slatecom_msg" ,
we didn't check if "rx_data" has enough room to hold that type.
The "rx_size" is read from slate to master fifo and if received
rx_size is less then "glink_slatecom_msg" then it could lead to
heap out of bounds read.
If received rx_size is less then the expected glink_slatecom_msg
then return back as a bad message.
Change-Id: Idde757ee70c7c88c22e4f036e6da0280e3b385d0
Signed-off-by: Kaushal Hooda <quic_khooda@quicinc.com>
(cherry picked from commit 7ddb61a6ac)
Add out of bound check while parsing the SPI
slave-to-master fifo.
Change-Id: I14f707307fa277b2f8a7b543d3cc5e9ebac885db
Signed-off-by: Ajit Kumar <quic_kajit@quicinc.com>
(cherry picked from commit 0950011ce6)
While parsing ESP IE from beacon/probe response frame,
the condition in loop to copy ESP_INFO from the ESP IE is
incorrect which will iterate for 5 times rather than 4 times,
this may cause OOB access.
data < ((uint8_t *)esp_ie + esp_ie->esp_len + 3)
Here adding 3 for esp_ie->esp_len, actually esp_len itself is
1 byte extra (esp_ len = ESP_ID_EXTN + ESP_INFO * 4),
but by adding 3 again will loop for one more iteration
this will cause OOB access.
Remove 3 in loop condition to avoid one more extra iteration
and ignore ESP_ID_EXTN element for total elements, in function
util_scan_update_esp_data.
Change-Id: Ia9226e483672369af36c6914e3ac914fe9de45e5
CRs-Fixed: 3710081
(cherry picked from commit 799a747940)
Currently, if a USB request that was queued by Raw Gadget is interrupted
(via a signal), wait_for_completion_interruptible returns -ERESTARTSYS.
Raw Gadget then attempts to propagate this value to userspace as a return
value from its ioctls. However, when -ERESTARTSYS is returned by a syscall
handler, the kernel internally restarts the syscall.
This doesn't allow userspace applications to interrupt requests queued by
Raw Gadget (which is required when the emulated device is asked to switch
altsettings). It also violates the implied interface of Raw Gadget that a
single ioctl must only queue a single USB request.
Instead, make Raw Gadget do what GadgetFS does: check whether the request
was interrupted (dequeued with status == -ECONNRESET) and report -EINTR to
userspace.
Bug: 254441685
Fixes: f2c2e717642c ("usb: gadget: add raw-gadget interface")
Cc: stable <stable@kernel.org>
Signed-off-by: Andrey Konovalov <andreyknvl@gmail.com>
Link: https://lore.kernel.org/r/0db45b1d7cc466e3d4d1ab353f61d63c977fbbc5.1698350424.git.andreyknvl@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit e8033bde451eddfb9b1bbd6e2d848c1b5c277222)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I1509b30c9962d6e695b268c183e41bdd551f1780
commit 60c0c230c6f046da536d3df8b39a20b9a9fd6af0 upstream.
rbtree lazy gc on insert might collect an end interval element that has
been just added in this transactions, skip end interval elements that
are not yet active.
Bug: 325477234
Fixes: f718863aca46 ("netfilter: nft_set_rbtree: fix overlap expiration walk")
Cc: stable@vger.kernel.org
Reported-by: lonial con <kongln9170@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 10e9cb3931)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I42f7bca418d47948292b15ace9f371b81ccd7fe8
Add condition check to make sure that the end address
of private entry does not go out of partition.
Change-Id: I88b3c69d86d90905b214c13a8c632b134b487a49
Signed-off-by: Sarannya S <quic_sarannya@quicinc.com>
Signed-off-by: Pranav Mahesh Phansalkar <quic_pphansal@quicinc.com>
Power count is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.
CRs-Fixed: 3691744.
Change-Id: I57d13435453195f8aab0c9aad4414d290274ff81
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>
(cherry picked from commit c9cd58783e)
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.
Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
(cherry picked from commit e7c4bb239b)
If iommu unmap fails and leaves dma or anon buffers still mapped in the
iommu, do not free them.
Change-Id: Ice0e1a59c1ac0ee7a9d62d8899966b84fa63d5ca
Signed-off-by: Lynus Vaz <quic_lvaz@quicinc.com>
Signed-off-by: Deepak Kumar <quic_dkumar@quicinc.com>
Power count is coming from user space which can be modified due to
access to shared memory. This change scopes the data locally so
as to avoid vulnerability of count being modified by external
means while executing due to being in shared memory.
CRs-Fixed: 3691744.
Change-Id: I57d13435453195f8aab0c9aad4414d290274ff81
Signed-off-by: Shivi Mangal <quic_smangal@quicinc.com>