FROMLIST: msm: IPA: add the check on intf query
The ipa_ioc_query_intf_rx_props structure comes from the ioctl handler, and it is verified that the size of rx buffer does not exceed the IPA_NUM_PROPS_MAX elements. It is also verified that the "entry->rx" buffer does not exceed IPA_NUM_PROPS_MAX when "entry" is allocated. However, the sizes of the buffer "rx->rx" and the buffer "entry->rx" are not guaranteed to be the same and will lead memory corruption issue. The fix is to add the check before memcpy. Bug: 34026243 Bug: 35048450 Bug: 35047780 Bug: 35047217 Change-Id: Idf5c2d32f47c1a1cffeaa5607193855188893ddb Signed-off-by:Skylar Chang <chiaweic@codeaurora.org> Signed-off-by:
Steve Pfetsch <spfetsch@google.com> (am from https://source.codeaurora.org/quic/la/kernel/ msm-3.18/commit/?id=cf0d31bc)
Loading
Please register or sign in to comment