diff --git a/drivers/android/binder.c b/drivers/android/binder.c index 723e5a919c20b33641a0cc4eb7ea2b7c9ed9f646..266ce581e75176e471ac290a19e742f13ceb7d59 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -3555,6 +3555,7 @@ static void binder_transaction(struct binder_proc *proc, */ copy_size = object_offset - user_offset; if (copy_size && (user_offset > object_offset || + object_offset > tr->data_size || binder_alloc_copy_user_to_buffer( &target_proc->alloc, t->buffer, user_offset,