From 1f2b96ab1a13be88c57c78be08168c0bb0080088 Mon Sep 17 00:00:00 2001 From: Saya Andy Date: Fri, 18 Sep 2026 21:45:43 +0700 Subject: fix: adapt patches for some 7.2.6 kernel updates to remoteproc and usb --- ...p2p-Use-length-limited-strncmp-for-compar.patch | 24 ++++++++++++++++++++++ 1 file changed, 24 insertions(+) create mode 100644 patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch (limited to 'patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch') diff --git a/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch b/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch new file mode 100644 index 0000000..7bbb199 --- /dev/null +++ b/patches/remoteproc/0003-soc-qcom-smp2p-Use-length-limited-strncmp-for-compar.patch @@ -0,0 +1,24 @@ +A rogue (or broken) remoteproc might not null-terminate its entry names. +Use strncmp() instead of strcmp() to avoid making out of bounds accesses in +that situation. + +Fixes: 50e99641413e ("soc: qcom: smp2p: Qualcomm Shared Memory Point to Point") +Signed-off-by: Stephan Gerhold +Signed-off-by: Abel Vesa +--- + drivers/soc/qcom/smp2p.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/drivers/soc/qcom/smp2p.c b/drivers/soc/qcom/smp2p.c +index 876648d0b..dcf222b19 100644 +--- a/drivers/soc/qcom/smp2p.c ++++ b/drivers/soc/qcom/smp2p.c +@@ -238,7 +238,7 @@ static void qcom_smp2p_notify_in(struct qcom_smp2p *smp2p) + for (i = smp2p->valid_entries; i < in->valid_entries; i++) { + list_for_each_entry(entry, &smp2p->inbound, node) { + memcpy(buf, in->entries[i].name, sizeof(buf)); +- if (!strcmp(buf, entry->name)) { ++ if (!strncmp(buf, entry->name, SMP2P_MAX_ENTRY_NAME)) { + entry->value = &in->entries[i].value; + break; + } -- cgit v1.3.1+17