Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 35f338e4 authored by Ernesto Ramos's avatar Ernesto Ramos Committed by Greg Kroah-Hartman
Browse files

staging: ti dspbridge: avoid possible NULL dereference panic



When dsp_notifications array is received from user,
dspbridge verifies the array has valid pointers
and dsp_notification structures. However, these
structures contain pointers that need to be
checked for valid handles.

Signed-off-by: default avatarErnesto Ramos <ernesto@ti.com>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@suse.de>
parent 019415ce
Loading
Loading
Loading
Loading
+8 −6
Original line number Diff line number Diff line
@@ -539,7 +539,7 @@ u32 mgrwrap_unregister_object(union trapped_args *args, void *pr_ctxt)
 */
u32 mgrwrap_wait_for_bridge_events(union trapped_args *args, void *pr_ctxt)
{
	int status = 0, real_status = 0;
	int status = 0;
	struct dsp_notification *anotifications[MAX_EVENTS];
	struct dsp_notification notifications[MAX_EVENTS];
	u32 index, i;
@@ -554,19 +554,21 @@ u32 mgrwrap_wait_for_bridge_events(union trapped_args *args, void *pr_ctxt)
	/* get the events */
	for (i = 0; i < count; i++) {
		CP_FM_USR(&notifications[i], anotifications[i], status, 1);
		if (!status) {
		if (status || !notifications[i].handle) {
			status = -EINVAL;
			break;
		}
		/* set the array of pointers to kernel structures */
		anotifications[i] = &notifications[i];
	}
	}
	if (!status) {
		real_status = mgr_wait_for_bridge_events(anotifications, count,
		status = mgr_wait_for_bridge_events(anotifications, count,
							 &index,
							 args->args_mgr_wait.
							 utimeout);
	}
	CP_TO_USR(args->args_mgr_wait.pu_index, &index, status, 1);
	return real_status;
	return status;
}

/*