diff --git a/drivers/android/binder.c b/drivers/android/binder.c index 9a1151c5e3ef..28117ddb9d6d 100644 --- a/drivers/android/binder.c +++ b/drivers/android/binder.c @@ -3326,6 +3326,7 @@ static void binder_transaction(struct binder_proc *proc, */ copy_size = object_offset - user_offset; if (copy_size && (user_offset > object_offset || + object_offset > tr->data_size || binder_alloc_copy_user_to_buffer( &target_proc->alloc, t->buffer, user_offset,