mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
media: v4l2-ctrls: validate AV1 tile counts
The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop
bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[]
arrays, as the divisor for context_update_tile_id, and their product
bounds the per-tile descriptor buffers, but std_validate_compound() does
not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose
tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose
product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the
consuming driver so the zero-initialised control that existing userspace
submits is still accepted.
Fixes: 9de30f5799 ("media: Add AV1 uAPI")
Assisted-by: Claude:claude-opus-4-8
Cc: stable@vger.kernel.org
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
This commit is contained in:
parent
dc694a9929
commit
439058ced6
|
|
@ -793,10 +793,30 @@ static int validate_av1_film_grain(struct v4l2_ctrl_av1_film_grain *fg)
|
|||
return 0;
|
||||
}
|
||||
|
||||
static int validate_av1_tile_info(struct v4l2_av1_tile_info *t)
|
||||
{
|
||||
/*
|
||||
* tile_cols and tile_rows index the per-tile descriptor arrays and
|
||||
* bound the tile loops in the stateless AV1 drivers; the product
|
||||
* bounds the total tile descriptor count.
|
||||
*/
|
||||
if (t->tile_cols > V4L2_AV1_MAX_TILE_COLS ||
|
||||
t->tile_rows > V4L2_AV1_MAX_TILE_ROWS)
|
||||
return -EINVAL;
|
||||
|
||||
if ((u32)t->tile_cols * t->tile_rows > V4L2_AV1_MAX_TILE_COUNT)
|
||||
return -EINVAL;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int validate_av1_frame(struct v4l2_ctrl_av1_frame *f)
|
||||
{
|
||||
int ret = 0;
|
||||
|
||||
ret = validate_av1_tile_info(&f->tile_info);
|
||||
if (ret)
|
||||
return ret;
|
||||
ret = validate_av1_quantization(&f->quantization);
|
||||
if (ret)
|
||||
return ret;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user