mirror of
https://github.com/torvalds/linux.git
synced 2026-09-14 16:10:02 +02:00
media: v4l2-ctrls: validate HEVC tile counts
The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from
column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[]
and use them as tile-loop bounds, but std_validate_compound() does not
bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling
enabled whose tile counts exceed the uAPI array capacity, mirroring the
existing compound-control range checks.
Fixes: 256fa39208 ("media: v4l: Add definitions for HEVC stateless decoding")
Assisted-by: Claude:claude-opus-4-8
Cc: stable@vger.kernel.org
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
This commit is contained in:
parent
10e59fbdef
commit
dc694a9929
|
|
@ -1253,6 +1253,18 @@ static int std_validate_compound(const struct v4l2_ctrl *ctrl, u32 idx,
|
|||
|
||||
p_hevc_pps->flags &=
|
||||
~V4L2_HEVC_PPS_FLAG_LOOP_FILTER_ACROSS_TILES_ENABLED;
|
||||
} else {
|
||||
/*
|
||||
* These count the entries the stateless HEVC drivers
|
||||
* read from column_width_minus1[] / row_height_minus1[]
|
||||
* and use as tile-loop bounds.
|
||||
*/
|
||||
if (p_hevc_pps->num_tile_columns_minus1 >=
|
||||
ARRAY_SIZE(p_hevc_pps->column_width_minus1))
|
||||
return -EINVAL;
|
||||
if (p_hevc_pps->num_tile_rows_minus1 >=
|
||||
ARRAY_SIZE(p_hevc_pps->row_height_minus1))
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (p_hevc_pps->flags &
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user