FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
sfr->buf_size is in shared memory and can be modified by malicious user. OOB write is possible when the size is made higher than actual sfr data buffer. Cap the size to allocated size for such cases. Signed-off-by:Vikash Garodia <quic_vgarodia@quicinc.com> (cherry picked from commit f4b21171 https://gitlab.freedesktop.org/linux-media/media-committers.git master) Change-Id: I483a5feff3dfa35dae8f444e57601d2d1d85246f Signed-off-by:
Gaviraju Doddabettahalli Bettegowda <quic_gdoddabe@quicinc.com>
Loading
Please sign in to comment