summaryrefslogtreecommitdiff
path: root/samples
diff options
context:
space:
mode:
authorTuomas Tynkkynen <ttynkkynen@nvidia.com>2012-07-30 12:40:45 +0300
committerSimone Willett <swillett@nvidia.com>2012-07-31 14:59:00 -0700
commitafb5a244504ac8535aa80781f0faf4d629d6dc32 (patch)
tree15eedd3f9790e5ca340bd1965fc860c2741993a7 /samples
parent524a9932de822961cd6fda49560af637bf8e9722 (diff)
video: tegra: nvmap: Fix two integer overflows.
nvmap_ioctl_pinop kmalloc's a temporary buffer, whose length is directly given by ioctl parameter from usermode. The total size of the buffer is not checked for overflow, which will cause a kernel panic with some inputs. Also, a sizeof() is applied to wrong type when calculating the amount of bytes to copy from userspace. nvmap_map_into_caller_ptr attempts to validate that the memory range to be mapped is correct, but integer overflow can cause the check to fail. This will lead to mapping wrong pages from the allocated handle later on, when the page fault handler gets called. Bug 1025502 Change-Id: I71a09c40c209dba9c5b37c3912e92a81e6f87e80 Signed-off-by: Tuomas Tynkkynen <ttynkkynen@nvidia.com>
Diffstat (limited to 'samples')
0 files changed, 0 insertions, 0 deletions