From patchwork Fri Nov 25 00:54:32 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Martin Blumenstingl X-Patchwork-Id: 9446375 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id 255B260235 for ; Fri, 25 Nov 2016 00:57:02 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 129F727FAE for ; Fri, 25 Nov 2016 00:57:02 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id 0593E27FB1; Fri, 25 Nov 2016 00:57:02 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.1 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, FREEMAIL_FROM, RCVD_IN_DNSWL_MED, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.9]) (using TLSv1.2 with cipher AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.wl.linuxfoundation.org (Postfix) with ESMTPS id D660827FAE for ; Fri, 25 Nov 2016 00:57:00 +0000 (UTC) Received: from localhost ([127.0.0.1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.85_2 #1 (Red Hat Linux)) id 1cA4nF-00075l-Bg; Fri, 25 Nov 2016 00:55:09 +0000 Received: from mail-wj0-x241.google.com ([2a00:1450:400c:c01::241]) by bombadil.infradead.org with esmtps (Exim 4.85_2 #1 (Red Hat Linux)) id 1cA4nB-0006lc-8n; Fri, 25 Nov 2016 00:55:06 +0000 Received: by mail-wj0-x241.google.com with SMTP id o2so400311wje.2; Thu, 24 Nov 2016 16:54:46 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlemail.com; s=20120113; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=LqO/AtRHzspoGwJcM9X1fsK6tWapxw5NvvyOQ9Fms9Q=; b=B+bM0ntbjDYMhx1x6K88EDDziP/psVtLn8XIQtq7pKwdKHHi8r/tyMIEM2iljstbEI k+U7T69y2wiFRsffmSQyW29Xrk7VLgHpnycStV4/P5AxNpSP5UL7QIvM6+oScIFc6Vx/ JLSuWF3VTpohSAOEmjf1Dz2Y1r0vYsZVkfql34SjYik0oli2YHad66W/Inw03XzZmxDK CSxk0IRF8/wfh3oXrlsT4NkqhvBS7Um6ScLBcfCIPLQSvlgBgH7ZJ4mlsXLxjRstYqGZ AtvB6JHGgoLJX4j4ObSPrfuWVxGtCM3RYoZ3ZvihiysrQUH16y5IM7/uMQvadzySfNmV TX4w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=LqO/AtRHzspoGwJcM9X1fsK6tWapxw5NvvyOQ9Fms9Q=; b=S1beYwD5h1FG3zbSsi/jEqJW+OUn+34a0QxZjkH+TZE+Am+m7DN+n4Z4SpnmjzNhQG E6kpaiQflGnUBx9Ob8b63h78CKPR0HFLXTWtpHBcALchZf8pVpLb5i/6MZeGeGH9oi/Z iK2wV4FPxRt7Jf4df4y9SkV1tRBVV0Dk8k9vTpypLaA1G3vHf7+Y/Fm2FEgejiehwH3c q+XmqmvMuNsLlZEVivL0KqHGZ4yuv2xt+Zar65dKan33LxRMZNNLYaQEtEG71V3sFWrl PX2xsufhKRaqdOn1yq/EzE92q5ZsRHQ1aiWeomCaAAP9UHJidH3RQV+fND8nV/IMLfLM /+7A== X-Gm-Message-State: AKaTC02s5HgvaugfsQuxelO83cp+ZdR+DSSvzo9XVlqVWVLDR8FFVXVMru8hqxpVlNawFA== X-Received: by 10.194.28.10 with SMTP id x10mr4773129wjg.157.1480035285407; Thu, 24 Nov 2016 16:54:45 -0800 (PST) Received: from blackbox.darklights.net (p5DE38BA9.dip0.t-ipconnect.de. [93.227.139.169]) by smtp.googlemail.com with ESMTPSA id g73sm10804181wme.16.2016.11.24.16.54.44 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 24 Nov 2016 16:54:44 -0800 (PST) From: Martin Blumenstingl To: sudeep.holla@arm.com, linux-arm-kernel@lists.infradead.org, linux-amlogic@lists.infradead.org Subject: [PATCH v2 2/2] firmware: arm_scpi: check the payload length in scpi_send_message Date: Fri, 25 Nov 2016 01:54:32 +0100 Message-Id: <20161125005432.1205-3-martin.blumenstingl@googlemail.com> X-Mailer: git-send-email 2.10.2 In-Reply-To: <20161125005432.1205-1-martin.blumenstingl@googlemail.com> References: <20161124001845.20830-1-martin.blumenstingl@googlemail.com> <20161125005432.1205-1-martin.blumenstingl@googlemail.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20161124_165505_553160_DF0BECCC X-CRM114-Status: UNSURE ( 9.17 ) X-CRM114-Notice: Please train this message. X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Martin Blumenstingl , narmstrong@baylibre.com MIME-Version: 1.0 Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+patchwork-linux-arm=patchwork.kernel.org@lists.infradead.org X-Virus-Scanned: ClamAV using ClamSMTP This adds a sanity check to ensure we're not writing data beyond the end of our rx_buf and tx_buf. Currently we are still far from reaching this limit, so this is a non-critical fix. Signed-off-by: Martin Blumenstingl --- drivers/firmware/arm_scpi.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/firmware/arm_scpi.c b/drivers/firmware/arm_scpi.c index 8c183d8..78ea8c7 100644 --- a/drivers/firmware/arm_scpi.c +++ b/drivers/firmware/arm_scpi.c @@ -538,6 +538,11 @@ static int scpi_send_message(u8 idx, void *tx_buf, unsigned int tx_len, scpi_info->num_chans; scpi_chan = scpi_info->channels + chan; + if (tx_len > scpi_chan->max_payload_len) + return -EINVAL; + if (rx_len > scpi_chan->max_payload_len) + return -EINVAL; + msg = get_scpi_xfer(scpi_chan); if (!msg) return -ENOMEM;