From: sashiko-bot@kernel.org
To: "Michael Freidkin" <freidkin@gmail.com>
Cc: neil.armstrong@linaro.org, linux-amlogic@lists.infradead.org,
media-ci@linuxtv.org
Subject: Re: [PATCH] media: meson: vdec: size capture planes from the aligned canvas
Date: Tue, 29 Sep 2026 21:48:10 +0000 [thread overview]
Message-ID: <20260929214811.4383B1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928165045.642354-1-freidkin@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] media: meson: vdec: integer overflow in get_output_size() causes OOB DMA write
--
commit 28bcd6a9db6c6247ecace49156692588db867097
Author: Michael Freidkin <freidkin@gmail.com>
media: meson: vdec: size capture planes from the aligned canvas
This commit aligns the width and height to 32 before calculating the output
size in get_output_size(). This fixes an issue where the allocated capture
planes were too small for the advertised stride when the width is not a
multiple of 32.
> diff --git a/drivers/staging/media/meson/vdec/vdec.c b/drivers/staging/media/meson/vdec/vdec.c
> index c18bf352b1996..be29d5a11c2e6 100644
> --- a/drivers/staging/media/meson/vdec/vdec.c
> +++ b/drivers/staging/media/meson/vdec/vdec.c
> @@ -34,7 +34,7 @@ struct dummy_buf {
>
> static u32 get_output_size(u32 width, u32 height)
> {
> - return ALIGN(width * height, SZ_64K);
> + return ALIGN(ALIGN(width, 32) * ALIGN(height, 32), SZ_64K);
[Severity: Critical]
Does this new alignment calculation introduce an integer overflow that
results in a 0-byte DMA buffer?
A crafted VP9 bitstream can provide untrusted dimensions up to 65535x65535.
The firmware parses these into param->p.width and param->p.height in
drivers/staging/media/meson/vdec/codec_vp9.c:codec_vp9_process_rpm(), which
passes them directly to amvdec_src_change(). The dimensions are assigned
to sess->width and sess->height without clamping.
If a user handles the resulting source change event by calling
VIDIOC_REQBUFS directly, skipping VIDIOC_S_FMT which would normally clamp
the dimensions, get_output_size() is called with 65535x65535.
When these dimensions are aligned to 32 here, ALIGN(65535, 32) *
ALIGN(65535, 32) evaluates to 65536 * 65536, or 4,294,967,296. Because
get_output_size() uses u32, this multiplication overflows and wraps
exactly to 0.
vdec_queue_setup() then fetches this overflowed output size (0) to
initialize the DMA plane sizes, bypassing size validations and requesting a
0-byte DMA buffer. The hardware would then attempt to decode the frame into
this tiny buffer, writing gigabytes of data out of bounds.
Prior to this patch, width * height for 65535x65535 was 4,294,836,225,
which did not overflow u32 and correctly caused a safe allocation failure.
> }
>
> u32 amvdec_get_output_size(struct amvdec_session *sess)
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260928165045.642354-1-freidkin@gmail.com?part=1
_______________________________________________
linux-amlogic mailing list
linux-amlogic@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-amlogic
prev parent reply other threads:[~2026-09-29 21:48 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 16:50 Michael Freidkin
2026-09-29 5:46 ` Dan Carpenter
2026-09-29 6:08 ` Michael Freidkin
2026-09-29 21:48 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929214811.4383B1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=freidkin@gmail.com \
--cc=linux-amlogic@lists.infradead.org \
--cc=media-ci@linuxtv.org \
--cc=neil.armstrong@linaro.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®