No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Vivek Yadav bca82b3563 msm: camera: isp: Fix potential illegal access in Acquire HW
Fix potential illegal acquire_hw memory access due to following
scenario. Even though ioctl is synchronous, the kernel performs
1. copy_from_user(&api_version, ...) — reads just the version.
2. Allocates buffer based on version.
3. copy_from_user(acquire_ptr, ...) — reads the full structure.

If another thread modifies the user-space buffer (cmd->handle)
between steps 1 and 3, the kernel will
* Allocate a buffer for version 1.
* But read data formatted for version 1, by modifying api version v2.
* Call the  isp_ctx: acquire_hw_in_acquired.
* Now even though the allocated strructure version is v1, in
  acquire_hw_in_acquired call to api of version v2 would get invoked.
* Leading to OOB reads/writes.

CRs-Fixed: 4216838
Change-Id: I88d1c76438b56d6ccfa014aa440a536ac5bdd27a
Signed-off-by: Vivek Yadav <viveyada@qti.qualcomm.com>
(cherry picked from commit 55273537c3c23152bba518402a96a86918e3f56c)
2026-02-09 16:53:04 +05:30
config msm: camera: config: Enable camera drivers for qcs610 2021-12-03 01:58:20 -08:00
drivers msm: camera: isp: Fix potential illegal access in Acquire HW 2026-02-09 16:53:04 +05:30
include/uapi msm: camera: ope: Increase max bl limit and max stripe to process 2021-11-26 12:12:16 +05:30
Makefile msm: camera: config: Enable camera drivers for qcs610 2021-12-03 01:58:20 -08:00