Fix for oobw in impd_manage_eq_complexity() due to eq_set_id

str_eq_instructions->eq_set_id is a 7 bit field read from bit stream,
whose value can be between 0 to 127.eq_set_id_valid_flag[] is an array
of size EQ_INSTRUCTIONS_COUNT_MAX(8).eq_set_id_valid_flag[] array is
accessed using eq_set_id as offset. str_eq_instructions->eq_set_id
value greater than EQ_INSTRUCTIONS_COUNT_MAX is causing OOB write

Bound check is added for str_eq_instructions->eq_set_id

Bug:119263248
Test: vendor
Change-Id: I3e10e4769fd8db130ffed8e5c703480e6a8c4312
This commit is contained in:
Ramesh Katuri 2018-11-16 17:22:09 +05:30 • committed by Ray Essick
parent 06c5d85bfd
commit cc2fdf7714

View file

@ -1080,6 +1080,9 @@ WORD32 impd_parse_eq_instructions(
str_eq_instructions->eq_set_id = (temp >> 5) & 0x3F;
if (str_eq_instructions->eq_set_id >= EQ_INSTRUCTIONS_COUNT_MAX)
return UNEXPECTED_ERROR;
str_eq_instructions->eq_set_complexity_level = (temp >> 1) & 0x0F;
dmix_id_present = temp & 0x01;