From 27d4a476f6aa84db74fcc5b65d87210d96b019cd Mon Sep 17 00:00:00 2001 From: Narender Ankam Date: Thu, 24 Aug 2017 15:06:02 +0530 Subject: msm: mdss: hdmi: correctly validate the cec msg frame size HDMI CEC message is being validated against the operand size (MAX_OPERAND_SIZE). Instead validate against the frame size (MAX_CEC_FRAME_SIZE). Change-Id: I9fd66781feedbe9bc1090b0e28ef9d814edcca5a Signed-off-by: Narender Ankam --- drivers/video/fbdev/msm/mdss_cec_core.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/video/fbdev/msm/mdss_cec_core.c b/drivers/video/fbdev/msm/mdss_cec_core.c index 4b53b01be709..1d9950494d65 100644 --- a/drivers/video/fbdev/msm/mdss_cec_core.c +++ b/drivers/video/fbdev/msm/mdss_cec_core.c @@ -1,4 +1,4 @@ -/* Copyright (c) 2015-2016, The Linux Foundation. All rights reserved. +/* Copyright (c) 2015-2017, The Linux Foundation. All rights reserved. * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License version 2 and @@ -681,7 +681,7 @@ static ssize_t cec_wta_msg(struct device *dev, } spin_unlock_irqrestore(&ctl->lock, flags); - if (msg->frame_size > MAX_OPERAND_SIZE) { + if (msg->frame_size > MAX_CEC_FRAME_SIZE) { pr_err("msg frame too big!\n"); ret = -EINVAL; goto end; -- cgit v1.2.3