Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 3961be10 authored by Linux Build Service Account's avatar Linux Build Service Account Committed by Gerrit - the friendly Code Review server
Browse files

Merge "soc: qcom: Avoid possible buffer overflow in service-locator"

parents 040d1247 68020103
Loading
Loading
Loading
Loading
+7 −4
Original line number Diff line number Diff line
@@ -266,10 +266,9 @@ static int service_locator_send_msg(struct pd_qmi_client_data *pd)
		if (!domains_read) {
			db_rev_count = pd->db_rev_count = resp->db_rev_count;
			pd->total_domains = resp->total_domains;
			if (!pd->total_domains && resp->domain_list_len) {
				pr_err("total domains not set\n");
				pd->total_domains = resp->domain_list_len;
			}
			if (!resp->total_domains)
				pr_info("No matching domains found\n");

			pd->domain_list = kmalloc(
					sizeof(struct servreg_loc_entry_v01) *
					resp->total_domains, GFP_KERNEL);
@@ -286,6 +285,10 @@ static int service_locator_send_msg(struct pd_qmi_client_data *pd)
			rc = -EAGAIN;
			goto out;
		}
		if (resp->domain_list_len >  resp->total_domains) {
			/* Always read total_domains from the response msg */
			resp->domain_list_len = resp->total_domains;
		}
		/* Copy the response*/
		store_get_domain_list_response(pd, resp, domains_read);
		domains_read += resp->domain_list_len;