A rogue (or broken) remoteproc might not null-terminate its entry names. Use strncmp() instead of strcmp() to avoid making out of bounds accesses in that situation. Fixes: 50e99641413e ("soc: qcom: smp2p: Qualcomm Shared Memory Point to Point") Signed-off-by: Stephan Gerhold Signed-off-by: Abel Vesa --- drivers/soc/qcom/smp2p.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/soc/qcom/smp2p.c b/drivers/soc/qcom/smp2p.c index 876648d0b..dcf222b19 100644 --- a/drivers/soc/qcom/smp2p.c +++ b/drivers/soc/qcom/smp2p.c @@ -238,7 +238,7 @@ static void qcom_smp2p_notify_in(struct qcom_smp2p *smp2p) for (i = smp2p->valid_entries; i < in->valid_entries; i++) { list_for_each_entry(entry, &smp2p->inbound, node) { memcpy(buf, in->entries[i].name, sizeof(buf)); - if (!strcmp(buf, entry->name)) { + if (!strncmp(buf, entry->name, SMP2P_MAX_ENTRY_NAME)) { entry->value = &in->entries[i].value; break; }