On Fri Jan 23 14:22:44 2026 -0500, Detlev Casanova wrote:
> The values of ext_sps_st_rps and ext_sps_lt_rps in struct rkvdec_hevc_run
> are not initialized when the respective controls are not set by userspace.
> 
> When this is the case, set them to NULL so the rkvdec_hevc_run_preamble
> function that parses controls does not access garbage data which leads to
> a panic on unaccessible memory.
> 
> Fixes: c9a59dc2acc7 ("media: rkvdec: Add HEVC support for the VDPU381 
> variant")
> Reported-by: Christian Hewitt <[email protected]>
> Suggested-by: Jonas Karlman <[email protected]>
> Signed-off-by: Detlev Casanova <[email protected]>
> Tested-by: Christian Hewitt <[email protected]>
> Reviewed-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Nicolas Dufresne <[email protected]>
> Signed-off-by: Mauro Carvalho Chehab <[email protected]>

Patch committed.

Thanks,
Mauro Carvalho Chehab

 drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c | 4 ++++
 1 file changed, 4 insertions(+)

---

diff --git a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c 
b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
index 28267ee30190..3119f3bc9f98 100644
--- a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
+++ b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
@@ -500,11 +500,15 @@ void rkvdec_hevc_run_preamble(struct rkvdec_ctx *ctx,
                ctrl = v4l2_ctrl_find(&ctx->ctrl_hdl,
                                      V4L2_CID_STATELESS_HEVC_EXT_SPS_ST_RPS);
                run->ext_sps_st_rps = ctrl ? ctrl->p_cur.p : NULL;
+       } else {
+               run->ext_sps_st_rps = NULL;
        }
        if (ctx->has_sps_lt_rps) {
                ctrl = v4l2_ctrl_find(&ctx->ctrl_hdl,
                                      V4L2_CID_STATELESS_HEVC_EXT_SPS_LT_RPS);
                run->ext_sps_lt_rps = ctrl ? ctrl->p_cur.p : NULL;
+       } else {
+               run->ext_sps_lt_rps = NULL;
        }
 
        rkvdec_run_preamble(ctx, &run->base);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to