firmware: cs_dsp: Fix OOB memory read access in KUnit test (wmfw info)
authorJaroslav Kysela <perex@perex.cz>
Fri, 23 May 2025 15:58:14 +0000 (17:58 +0200)
committerMark Brown <broonie@kernel.org>
Mon, 26 May 2025 10:33:51 +0000 (11:33 +0100)
KASAN reported out of bounds access - cs_dsp_mock_wmfw_add_info(),
because the source string length was rounded up to the allocation size.

Cc: Simon Trimmer <simont@opensource.cirrus.com>
Cc: Charles Keepax <ckeepax@opensource.cirrus.com>
Cc: Richard Fitzgerald <rf@opensource.cirrus.com>
Cc: patches@opensource.cirrus.com
Cc: stable@vger.kernel.org
Signed-off-by: Jaroslav Kysela <perex@perex.cz>
Reviewed-by: Richard Fitzgerald <rf@opensource.cirrus.com>
Link: https://patch.msgid.link/20250523155814.1256762-1-perex@perex.cz
Signed-off-by: Mark Brown <broonie@kernel.org>
drivers/firmware/cirrus/test/cs_dsp_mock_wmfw.c

index 934d40a4d7098a6241a9bf1ee98337269a6bd436..5e1d5a810afeab84c05777375b0995b68d5dfc9c 100644 (file)
@@ -133,10 +133,11 @@ void cs_dsp_mock_wmfw_add_info(struct cs_dsp_mock_wmfw_builder *builder,
 
        if (info_len % 4) {
                /* Create a padded string with length a multiple of 4 */
+               size_t copy_len = info_len;
                info_len = round_up(info_len, 4);
                tmp = kunit_kzalloc(builder->test_priv->test, info_len, GFP_KERNEL);
                KUNIT_ASSERT_NOT_ERR_OR_NULL(builder->test_priv->test, tmp);
-               memcpy(tmp, info, info_len);
+               memcpy(tmp, info, copy_len);
                info = tmp;
        }