From: Vikash Garodia <quic_vgarodia@quicinc.com>
To: Stanimir Varbanov <stanimir.k.varbanov@gmail.com>,
Bryan O'Donoghue <bryan.odonoghue@linaro.org>,
Mauro Carvalho Chehab <mchehab@kernel.org>
Cc: <linux-media@vger.kernel.org>, <linux-arm-msm@vger.kernel.org>,
<linux-kernel@vger.kernel.org>,
Vikash Garodia <quic_vgarodia@quicinc.com>,
<stable@vger.kernel.org>
Subject: [PATCH 0/4] Venus driver fixes to avoid possible OOB accesses
Date: Tue, 5 Nov 2024 14:24:53 +0530 [thread overview]
Message-ID: <20241105-venus_oob-v1-0-8d4feedfe2bb@quicinc.com> (raw)
This series primarily adds check at relevant places in venus driver where there
are possible OOB accesses due to unexpected payload from venus firmware. The
patches describes the specific OOB possibility.
Please review and share your feedback.
Signed-off-by: Vikash Garodia <quic_vgarodia@quicinc.com>
---
Vikash Garodia (4):
media: venus: hfi_parser: add check to avoid out of bound access
media: venus: hfi_parser: avoid OOB access beyond payload word count
media: venus: hfi: add check to handle incorrect queue size
media: venus: hfi: add a check to handle OOB in sfr region
drivers/media/platform/qcom/venus/hfi_parser.c | 6 +++++-
drivers/media/platform/qcom/venus/hfi_venus.c | 15 +++++++++++++--
2 files changed, 18 insertions(+), 3 deletions(-)
---
base-commit: c7ccf3683ac9746b263b0502255f5ce47f64fe0a
change-id: 20241104-venus_oob-0343b143d61d
Best regards,
--
Vikash Garodia <quic_vgarodia@quicinc.com>
next reply other threads:[~2024-11-05 8:55 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-05 8:54 Vikash Garodia [this message]
2024-11-05 8:54 ` [PATCH 1/4] media: venus: hfi_parser: add check to avoid out of bound access Vikash Garodia
2024-11-05 10:51 ` Bryan O'Donoghue
2024-11-06 7:25 ` Vikash Garodia
2024-11-06 10:23 ` Bryan O'Donoghue
2024-11-07 8:24 ` Vikash Garodia
2024-11-05 13:55 ` Dmitry Baryshkov
2024-11-07 8:17 ` Vikash Garodia
2024-11-07 10:41 ` Dmitry Baryshkov
2024-11-07 12:07 ` Bryan O'Donoghue
2024-11-07 13:02 ` Vikash Garodia
2024-11-07 13:22 ` Dmitry Baryshkov
2024-11-07 13:35 ` Vikash Garodia
2024-11-07 13:54 ` Dmitry Baryshkov
2024-11-08 11:43 ` Bryan O'Donoghue
2024-11-11 14:02 ` Vikash Garodia
2024-11-11 14:04 ` Vikash Garodia
2024-11-05 8:54 ` [PATCH 2/4] media: venus: hfi_parser: avoid OOB access beyond payload word count Vikash Garodia
2024-11-05 11:15 ` Bryan O'Donoghue
2024-11-11 14:36 ` Vikash Garodia
2024-11-11 23:43 ` Bryan O'Donoghue
2024-11-12 8:05 ` Vikash Garodia
2024-11-12 11:17 ` Bryan O'Donoghue
2024-11-12 12:58 ` Vikash Garodia
2024-11-12 13:00 ` Bryan O'Donoghue
2024-11-05 8:54 ` [PATCH 3/4] media: venus: hfi: add check to handle incorrect queue size Vikash Garodia
2024-11-05 11:23 ` Bryan O'Donoghue
2024-11-05 8:54 ` [PATCH 4/4] media: venus: hfi: add a check to handle OOB in sfr region Vikash Garodia
2024-11-05 11:27 ` Bryan O'Donoghue
2024-11-05 13:58 ` Dmitry Baryshkov
2024-11-06 7:21 ` Vikash Garodia
-- strict thread matches above, loose matches on Subject: below --
2023-07-27 4:34 [PATCH 0/4] Venus driver fixes to avoid possible OOB accesses Vikash Garodia
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20241105-venus_oob-v1-0-8d4feedfe2bb@quicinc.com \
--to=quic_vgarodia@quicinc.com \
--cc=bryan.odonoghue@linaro.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=stable@vger.kernel.org \
--cc=stanimir.k.varbanov@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®