tee: qcom: prevent potential off by one read
Re-order these checks to check if "i" is a valid array index before using
it. This prevents a potential off by one read access.
Fixes: d6e290837e ("tee: add Qualcomm TEE driver")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: Sumit Garg <sumit.garg@oss.qualcomm.com>
Signed-off-by: Jens Wiklander <jens.wiklander@linaro.org>
This commit is contained in:
committed by
Jens Wiklander
parent
dcc7a571a3
commit
b14bb2e782
@@ -308,7 +308,7 @@ out_failed:
|
||||
}
|
||||
|
||||
/* Release any IO and OO objects not processed. */
|
||||
for (; u[i].type && i < num_params; i++) {
|
||||
for (; i < num_params && u[i].type; i++) {
|
||||
if (u[i].type == QCOMTEE_ARG_TYPE_OO ||
|
||||
u[i].type == QCOMTEE_ARG_TYPE_IO)
|
||||
qcomtee_object_put(u[i].o);
|
||||
|
||||
Reference in New Issue
Block a user