aboutsummaryrefslogtreecommitdiffci
path: root/patches/remoteproc/0002-soc-qcom-smp2p-Ensure-there-is-enough-space-for-outb.patch
blob: 49e7de32fbdd7565a4026ed50e88ed5e9dffecce (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
The SMP2P SMEM item has limited space for outbound entries, but the DT can
specify any number of entries. Add a check to prevent out of bounds writes
when an invalid DT specifies more entries than expected.

Fixes: 50e99641413e ("soc: qcom: smp2p: Qualcomm Shared Memory Point to Point")
Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
---
 drivers/soc/qcom/smp2p.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/soc/qcom/smp2p.c b/drivers/soc/qcom/smp2p.c
index 1ea4d35c6..876648d0b 100644
--- a/drivers/soc/qcom/smp2p.c
+++ b/drivers/soc/qcom/smp2p.c
@@ -441,6 +441,9 @@ static int qcom_smp2p_outbound_entry(struct qcom_smp2p *smp2p,
 	struct smp2p_smem_item *out = smp2p->out;
 	char buf[SMP2P_MAX_ENTRY_NAME] = {};
 
+	if (out->valid_entries == out->total_entries)
+		return -ENOMEM;
+
 	/* Allocate an entry from the smem item */
 	strscpy(buf, entry->name, SMP2P_MAX_ENTRY_NAME);
 	memcpy(out->entries[out->valid_entries].name, buf, SMP2P_MAX_ENTRY_NAME);