mirror of https://lore.kernel.org/linux-amlogic/
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Michael Freidkin" <freidkin@gmail.com>
Cc: neil.armstrong@linaro.org, linux-amlogic@lists.infradead.org,
	media-ci@linuxtv.org
Subject: Re: [PATCH] media: meson: vdec: size capture planes from the aligned canvas
Date: Tue, 29 Sep 2026 21:48:10 +0000	[thread overview]
Message-ID: <20260929214811.4383B1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928165045.642354-1-freidkin@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] media: meson: vdec: integer overflow in get_output_size() causes OOB DMA write
--

commit 28bcd6a9db6c6247ecace49156692588db867097
Author: Michael Freidkin <freidkin@gmail.com>

media: meson: vdec: size capture planes from the aligned canvas

This commit aligns the width and height to 32 before calculating the output
size in get_output_size(). This fixes an issue where the allocated capture
planes were too small for the advertised stride when the width is not a
multiple of 32.

> diff --git a/drivers/staging/media/meson/vdec/vdec.c b/drivers/staging/media/meson/vdec/vdec.c
> index c18bf352b1996..be29d5a11c2e6 100644
> --- a/drivers/staging/media/meson/vdec/vdec.c
> +++ b/drivers/staging/media/meson/vdec/vdec.c
> @@ -34,7 +34,7 @@ struct dummy_buf {
>  
>  static u32 get_output_size(u32 width, u32 height)
>  {
> -	return ALIGN(width * height, SZ_64K);
> +	return ALIGN(ALIGN(width, 32) * ALIGN(height, 32), SZ_64K);

[Severity: Critical]
Does this new alignment calculation introduce an integer overflow that
results in a 0-byte DMA buffer?

A crafted VP9 bitstream can provide untrusted dimensions up to 65535x65535.
The firmware parses these into param->p.width and param->p.height in
drivers/staging/media/meson/vdec/codec_vp9.c:codec_vp9_process_rpm(), which
passes them directly to amvdec_src_change(). The dimensions are assigned
to sess->width and sess->height without clamping.

If a user handles the resulting source change event by calling
VIDIOC_REQBUFS directly, skipping VIDIOC_S_FMT which would normally clamp
the dimensions, get_output_size() is called with 65535x65535.

When these dimensions are aligned to 32 here, ALIGN(65535, 32) *
ALIGN(65535, 32) evaluates to 65536 * 65536, or 4,294,967,296. Because
get_output_size() uses u32, this multiplication overflows and wraps
exactly to 0.

vdec_queue_setup() then fetches this overflowed output size (0) to
initialize the DMA plane sizes, bypassing size validations and requesting a
0-byte DMA buffer. The hardware would then attempt to decode the frame into
this tiny buffer, writing gigabytes of data out of bounds.

Prior to this patch, width * height for 65535x65535 was 4,294,836,225,
which did not overflow u32 and correctly caused a safe allocation failure.

>  }
>  
>  u32 amvdec_get_output_size(struct amvdec_session *sess)

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165045.642354-1-freidkin@gmail.com?part=1

_______________________________________________
linux-amlogic mailing list
linux-amlogic@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-amlogic

      parent reply	other threads:[~2026-09-29 21:48 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 16:50 Michael Freidkin
2026-09-29  5:46 ` Dan Carpenter
2026-09-29  6:08   ` Michael Freidkin
2026-09-29 21:48 ` sashiko-bot [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929214811.4383B1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=freidkin@gmail.com \
    --cc=linux-amlogic@lists.infradead.org \
    --cc=media-ci@linuxtv.org \
    --cc=neil.armstrong@linaro.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®