Diffstat (limited to 'patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch')
| -rw-r--r-- | patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch | 24 |
1 files changed, 0 insertions, 24 deletions
diff --git a/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch b/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch deleted file mode 100644 index 7bbb199..0000000 --- a/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch +++ /dev/null @@ -1,24 +0,0 @@ -A rogue (or broken) remoteproc might not null-terminate its entry names. -Use strncmp() instead of strcmp() to avoid making out of bounds accesses in -that situation. - -Fixes: 50e99641413e ("soc: qcom: smp2p: Qualcomm Shared Memory Point to Point") -Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org> -Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com> ---- - drivers/soc/qcom/smp2p.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/drivers/soc/qcom/smp2p.c b/drivers/soc/qcom/smp2p.c -index 876648d0b..dcf222b19 100644 ---- a/drivers/soc/qcom/smp2p.c -+++ b/drivers/soc/qcom/smp2p.c -@@ -238,7 +238,7 @@ static void qcom_smp2p_notify_in(struct qcom_smp2p *smp2p) - for (i = smp2p->valid_entries; i < in->valid_entries; i++) { - list_for_each_entry(entry, &smp2p->inbound, node) { - memcpy(buf, in->entries[i].name, sizeof(buf)); -- if (!strcmp(buf, entry->name)) { -+ if (!strncmp(buf, entry->name, SMP2P_MAX_ENTRY_NAME)) { - entry->value = &in->entries[i].value; - break; - } |