msm:ADSPRPC :Fix to avoid Use after free in fastrpc_internal_munmap
Added a check to validate map before freeing it to avoid Use after
free scenario.
Change-Id: Ic723a4fe964a4909119663500018f2a07976105b
Signed-off-by: Vamsi krishna Gattupalli <vgattupa@codeaurora.org>
diff --git a/drivers/char/adsprpc.c b/drivers/char/adsprpc.c
index 03ccd6c..4069e2e 100644
--- a/drivers/char/adsprpc.c
+++ b/drivers/char/adsprpc.c
@@ -2728,13 +2728,15 @@
mutex_unlock(&fl->fl_map_mutex);
if (err)
goto bail;
- VERIFY(err, !fastrpc_munmap_on_dsp(fl, map->raddr,
- map->phys, map->size, map->flags));
- if (err)
- goto bail;
- mutex_lock(&fl->fl_map_mutex);
- fastrpc_mmap_free(map, 0);
- mutex_unlock(&fl->fl_map_mutex);
+ if (map) {
+ VERIFY(err, !fastrpc_munmap_on_dsp(fl, map->raddr,
+ map->phys, map->size, map->flags));
+ if (err)
+ goto bail;
+ mutex_lock(&fl->fl_map_mutex);
+ fastrpc_mmap_free(map, 0);
+ mutex_unlock(&fl->fl_map_mutex);
+ }
bail:
if (err && map) {
mutex_lock(&fl->fl_map_mutex);