aboutsummaryrefslogtreecommitdiffstats
path: root/drivers/staging
diff options
context:
space:
mode:
authorAl Viro <viro@zeniv.linux.org.uk>2012-08-15 18:23:36 -0400
committerAl Viro <viro@zeniv.linux.org.uk>2012-09-26 21:08:51 -0400
commita79f41ed9786b75ebe75e52295ad54049b8551b6 (patch)
treed693d2ec11da1a622266daa09e26167a3f66c123 /drivers/staging
parentc921b40d6201f7ec7b1edf7ea9a844f93e1a27f4 (diff)
binder: don't allow mmap() by process other than proc->tsk
we really shouldn't do get_files_struct() on a different process and use it to modify the sucker later on. Signed-off-by: Al Viro <viro@zeniv.linux.org.uk>
Diffstat (limited to 'drivers/staging')
-rw-r--r--drivers/staging/android/binder.c5
1 files changed, 4 insertions, 1 deletions
diff --git a/drivers/staging/android/binder.c b/drivers/staging/android/binder.c
index 574e99210c3..b9a534c46aa 100644
--- a/drivers/staging/android/binder.c
+++ b/drivers/staging/android/binder.c
@@ -2793,6 +2793,9 @@ static int binder_mmap(struct file *filp, struct vm_area_struct *vma)
2793 const char *failure_string; 2793 const char *failure_string;
2794 struct binder_buffer *buffer; 2794 struct binder_buffer *buffer;
2795 2795
2796 if (proc->tsk != current)
2797 return -EINVAL;
2798
2796 if ((vma->vm_end - vma->vm_start) > SZ_4M) 2799 if ((vma->vm_end - vma->vm_start) > SZ_4M)
2797 vma->vm_end = vma->vm_start + SZ_4M; 2800 vma->vm_end = vma->vm_start + SZ_4M;
2798 2801
@@ -2857,7 +2860,7 @@ static int binder_mmap(struct file *filp, struct vm_area_struct *vma)
2857 binder_insert_free_buffer(proc, buffer); 2860 binder_insert_free_buffer(proc, buffer);
2858 proc->free_async_space = proc->buffer_size / 2; 2861 proc->free_async_space = proc->buffer_size / 2;
2859 barrier(); 2862 barrier();
2860 proc->files = get_files_struct(proc->tsk); 2863 proc->files = get_files_struct(current);
2861 proc->vma = vma; 2864 proc->vma = vma;
2862 proc->vma_vm_mm = vma->vm_mm; 2865 proc->vma_vm_mm = vma->vm_mm;
2863 2866