media: v4l2-ctrls: validate HEVC tile counts

The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from
column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[]
and use them as tile-loop bounds, but std_validate_compound() does not
bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling
enabled whose tile counts exceed the uAPI array capacity, mirroring the
existing compound-control range checks.

Fixes: 256fa39208 ("media: v4l: Add definitions for HEVC stateless decoding")
Assisted-by: Claude:claude-opus-4-8
Cc: stable@vger.kernel.org
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Benjamin Gaignard <benjamin.gaignard@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
This commit is contained in:
Michael Bommarito 2026-06-16 22:18:58 -04:00 committed by Hans Verkuil
parent 10e59fbdef
commit dc694a9929

View File

@ -1253,6 +1253,18 @@ static int std_validate_compound(const struct v4l2_ctrl *ctrl, u32 idx,
p_hevc_pps->flags &=
~V4L2_HEVC_PPS_FLAG_LOOP_FILTER_ACROSS_TILES_ENABLED;
} else {
/*
* These count the entries the stateless HEVC drivers
* read from column_width_minus1[] / row_height_minus1[]
* and use as tile-loop bounds.
*/
if (p_hevc_pps->num_tile_columns_minus1 >=
ARRAY_SIZE(p_hevc_pps->column_width_minus1))
return -EINVAL;
if (p_hevc_pps->num_tile_rows_minus1 >=
ARRAY_SIZE(p_hevc_pps->row_height_minus1))
return -EINVAL;
}
if (p_hevc_pps->flags &