ASoC: SOF: amd: require full ACP header for ACP7 signed firmware

ACP7.B/7.F signed images read SizeFWSigned from a fixed offset inside
the ACP header. Reject firmware buffers shorter than the header so we
never read past the end of the supplied image.

Signed-off-by: Vijendar Mukunda <Vijendar.Mukunda@amd.com>
Reviewed-by: Bard Liao <yung-chuan.liao@linux.intel.com>
Link: https://patch.msgid.link/20260701095759.1012929-9-Vijendar.Mukunda@amd.com
Signed-off-by: Mark Brown <broonie@kernel.org>
This commit is contained in:
Vijendar Mukunda 2026-07-01 15:25:09 +05:30 committed by Mark Brown
parent cbdafd2acd
commit d6869ae07d
No known key found for this signature in database
GPG Key ID: 24D68B725D5487D0

View File

@ -176,6 +176,11 @@ int acp_dsp_pre_fw_run(struct snd_sof_dev *sdev)
if (adata->pci_rev >= ACP7B_PCI_ID) {
if (adata->acp_sof_signed_firmware_image) {
if (adata->fw_bin_size <= ACP_IMAGE_HEADER_SIZE) {
dev_err(sdev->dev, "Invalid signed firmware size %u\n",
adata->fw_bin_size);
return -EINVAL;
}
size_fw = get_unaligned_le32(adata->bin_buf +
ACP_IMAGE_HDR_SIZE_FW_SIGNED_OFF);
size_fw += ACP_IMAGE_HEADER_SIZE;