On Fri Jan 23 14:22:44 2026 -0500, Detlev Casanova wrote:
> The values of ext_sps_st_rps and ext_sps_lt_rps in struct rkvdec_hevc_run
> are not initialized when the respective controls are not set by userspace.
>
> When this is the case, set them to NULL so the rkvdec_hevc_run_preamble
> function that parses controls does not access garbage data which leads to
> a panic on unaccessible memory.
>
> Fixes: c9a59dc2acc7 ("media: rkvdec: Add HEVC support for the VDPU381
> variant")
> Reported-by: Christian Hewitt <[email protected]>
> Suggested-by: Jonas Karlman <[email protected]>
> Signed-off-by: Detlev Casanova <[email protected]>
> Tested-by: Christian Hewitt <[email protected]>
> Reviewed-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Mauro Carvalho Chehab <[email protected]>
Patch committed.
Thanks,
Mauro Carvalho Chehab
drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c | 4 ++++
1 file changed, 4 insertions(+)
---
diff --git a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
index 28267ee30190..3119f3bc9f98 100644
--- a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
+++ b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
@@ -500,11 +500,15 @@ void rkvdec_hevc_run_preamble(struct rkvdec_ctx *ctx,
ctrl = v4l2_ctrl_find(&ctx->ctrl_hdl,
V4L2_CID_STATELESS_HEVC_EXT_SPS_ST_RPS);
run->ext_sps_st_rps = ctrl ? ctrl->p_cur.p : NULL;
+ } else {
+ run->ext_sps_st_rps = NULL;
}
if (ctx->has_sps_lt_rps) {
ctrl = v4l2_ctrl_find(&ctx->ctrl_hdl,
V4L2_CID_STATELESS_HEVC_EXT_SPS_LT_RPS);
run->ext_sps_lt_rps = ctrl ? ctrl->p_cur.p : NULL;
+ } else {
+ run->ext_sps_lt_rps = NULL;
}
rkvdec_run_preamble(ctx, &run->base);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]