aboutsummaryrefslogtreecommitdiffci
path: root/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch
diff refs
from: back
to: back
| flip
diff options
context:
space:
mode:
Diffstat (limited to 'patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch')
-rw-r--r--patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch24
1 files changed, 0 insertions, 24 deletions
diff --git a/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch b/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch
deleted file mode 100644
index 7bbb199..0000000
--- a/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch
+++ /dev/null
@@ -1,24 +0,0 @@
-A rogue (or broken) remoteproc might not null-terminate its entry names.
-Use strncmp() instead of strcmp() to avoid making out of bounds accesses in
-that situation.
-
-Fixes: 50e99641413e ("soc: qcom: smp2p: Qualcomm Shared Memory Point to Point")
-Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
-Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
----
- drivers/soc/qcom/smp2p.c | 2 +-
- 1 file changed, 1 insertion(+), 1 deletion(-)
-
-diff --git a/drivers/soc/qcom/smp2p.c b/drivers/soc/qcom/smp2p.c
-index 876648d0b..dcf222b19 100644
---- a/drivers/soc/qcom/smp2p.c
-+++ b/drivers/soc/qcom/smp2p.c
-@@ -238,7 +238,7 @@ static void qcom_smp2p_notify_in(struct qcom_smp2p *smp2p)
- for (i = smp2p->valid_entries; i < in->valid_entries; i++) {
- list_for_each_entry(entry, &smp2p->inbound, node) {
- memcpy(buf, in->entries[i].name, sizeof(buf));
-- if (!strcmp(buf, entry->name)) {
-+ if (!strncmp(buf, entry->name, SMP2P_MAX_ENTRY_NAME)) {
- entry->value = &in->entries[i].value;
- break;
- }