[media] media: vb2: add length check for mmap
authorSeung-Woo Kim <sw0312.kim@samsung.com>
Fri, 12 Apr 2013 02:57:57 +0000 (23:57 -0300)
committerMauro Carvalho Chehab <mchehab@redhat.com>
Mon, 15 Apr 2013 01:37:26 +0000 (22:37 -0300)
The length of mmap() can be bigger than length of vb2 buffer, so
it should be checked.

Signed-off-by: Seung-Woo Kim <sw0312.kim@samsung.com>
Acked-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Mauro Carvalho Chehab <mchehab@redhat.com>
drivers/media/v4l2-core/videobuf2-core.c

index 02bb5e72165740b024cee8e70b79558c2b473f45..58c17444d22faf4c1117383c1a86698aed2450e7 100644 (file)
@@ -1886,6 +1886,11 @@ int vb2_mmap(struct vb2_queue *q, struct vm_area_struct *vma)
 
        vb = q->bufs[buffer];
 
+       if (vb->v4l2_planes[plane].length < (vma->vm_end - vma->vm_start)) {
+               dprintk(1, "Invalid length\n");
+               return -EINVAL;
+       }
+
        ret = call_memop(q, mmap, vb->planes[plane].mem_priv, vma);
        if (ret)
                return ret;