Files
open-amp/lib
Ben Levinsky 49780d11b4 rpmsg: rpc: Validate client reply lengths
The RPC client reads the reply ID and status without checking that the
remote message contains the fixed reply header. It also passes the
total message length to callbacks that receive a parameters pointer,
making the reported length include the header bytes.

Reject replies shorter than the fixed header and pass callbacks only
the number of bytes that follow it.

Signed-off-by: Ben Levinsky <ben.levinsky@amd.com>
Assisted-by: Codex:GPT-5
2026-09-21 09:54:50 +02:00
..
…