mirror of
https://github.com/hardkernel/linux.git
synced 2026-06-05 10:31:46 +09:00
firmware: cs_dsp: Return error if block header overflows file
[ Upstream commit 959fe01e85b7241e3ec305d657febbe82da16a02 ]
Return an error from cs_dsp_power_up() if a block header is longer
than the amount of data left in the file.
The previous code in cs_dsp_load() and cs_dsp_load_coeff() would loop
while there was enough data left in the file for a valid region. This
protected against overrunning the end of the file data, but it didn't
abort the file processing with an error.
Signed-off-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Fixes: f6bc909e76 ("firmware: cs_dsp: add driver to support firmware loading on Cirrus Logic DSPs")
Link: https://patch.msgid.link/20240627141432.93056-3-rf@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
fd035f0810
commit
b8be70566b
@@ -1348,8 +1348,13 @@ static int cs_dsp_load(struct cs_dsp *dsp, const struct firmware *firmware,
|
|||||||
cs_dsp_dbg(dsp, "%s: timestamp %llu\n", file,
|
cs_dsp_dbg(dsp, "%s: timestamp %llu\n", file,
|
||||||
le64_to_cpu(footer->timestamp));
|
le64_to_cpu(footer->timestamp));
|
||||||
|
|
||||||
while (pos < firmware->size &&
|
while (pos < firmware->size) {
|
||||||
sizeof(*region) < firmware->size - pos) {
|
/* Is there enough data for a complete block header? */
|
||||||
|
if (sizeof(*region) > firmware->size - pos) {
|
||||||
|
ret = -EOVERFLOW;
|
||||||
|
goto out_fw;
|
||||||
|
}
|
||||||
|
|
||||||
region = (void *)&(firmware->data[pos]);
|
region = (void *)&(firmware->data[pos]);
|
||||||
region_name = "Unknown";
|
region_name = "Unknown";
|
||||||
reg = 0;
|
reg = 0;
|
||||||
@@ -2037,8 +2042,13 @@ static int cs_dsp_load_coeff(struct cs_dsp *dsp, const struct firmware *firmware
|
|||||||
pos = le32_to_cpu(hdr->len);
|
pos = le32_to_cpu(hdr->len);
|
||||||
|
|
||||||
blocks = 0;
|
blocks = 0;
|
||||||
while (pos < firmware->size &&
|
while (pos < firmware->size) {
|
||||||
sizeof(*blk) < firmware->size - pos) {
|
/* Is there enough data for a complete block header? */
|
||||||
|
if (sizeof(*blk) > firmware->size - pos) {
|
||||||
|
ret = -EOVERFLOW;
|
||||||
|
goto out_fw;
|
||||||
|
}
|
||||||
|
|
||||||
blk = (void *)(&firmware->data[pos]);
|
blk = (void *)(&firmware->data[pos]);
|
||||||
|
|
||||||
type = le16_to_cpu(blk->type);
|
type = le16_to_cpu(blk->type);
|
||||||
|
|||||||
Reference in New Issue
Block a user