mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-06 03:45:24 -04:00
No description
- C 98.2%
- Assembly 1%
- Makefile 0.3%
- Shell 0.2%
- Python 0.1%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Fix potential illegal acquire_hw memory access due to following scenario. Even though ioctl is synchronous, the kernel performs 1. copy_from_user(&api_version, ...) — reads just the version. 2. Allocates buffer based on version. 3. copy_from_user(acquire_ptr, ...) — reads the full structure. If another thread modifies the user-space buffer (cmd->handle) between steps 1 and 3, the kernel will * Allocate a buffer for version 1. * But read data formatted for version 1, by modifying api version v2. * Call the isp_ctx: acquire_hw_in_acquired. * Now even though the allocated strructure version is v1, in acquire_hw_in_acquired call to api of version v2 would get invoked. * Leading to OOB reads/writes. CRs-Fixed: 4216838 Change-Id: I88d1c76438b56d6ccfa014aa440a536ac5bdd27a Signed-off-by: Vivek Yadav <viveyada@qti.qualcomm.com> (cherry picked from commit 55273537c3c23152bba518402a96a86918e3f56c) |
||
| config | ||
| drivers | ||
| include/uapi | ||
| Makefile | ||