diff --git a/drivers/android/binder.c b/drivers/android/binder.c index fad1f742197f1023cff0ca3ae23d40de0d6792ea..282b0495da34a1ba0a06d996337b503389a99c94 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -3530,6 +3530,7 @@ static void binder_transaction(struct binder_proc *proc, */ copy_size = object_offset - user_offset; if (copy_size && (user_offset > object_offset || + object_offset > tr->data_size || binder_alloc_copy_user_to_buffer( &target_proc->alloc, t->buffer, user_offset,