On Tue Jun 16 22:18:58 2026 -0400, Michael Bommarito wrote:
> The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from
> column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[]
> and use them as tile-loop bounds, but std_validate_compound() does not
> bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling
> enabled whose tile counts exceed the uAPI array capacity, mirroring the
> existing compound-control range checks.
> 
> Fixes: 256fa3920874 ("media: v4l: Add definitions for HEVC stateless 
> decoding")
> Assisted-by: Claude:claude-opus-4-8
> Cc: [email protected]
> Signed-off-by: Michael Bommarito <[email protected]>
> Reviewed-by: Benjamin Gaignard <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/v4l2-core/v4l2-ctrls-core.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

---

diff --git a/drivers/media/v4l2-core/v4l2-ctrls-core.c 
b/drivers/media/v4l2-core/v4l2-ctrls-core.c
index 5b8a594fb9e2..9b6121a3a2d2 100644
--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
+++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
@@ -1253,6 +1253,18 @@ static int std_validate_compound(const struct v4l2_ctrl 
*ctrl, u32 idx,
 
                        p_hevc_pps->flags &=
                                
~V4L2_HEVC_PPS_FLAG_LOOP_FILTER_ACROSS_TILES_ENABLED;
+               } else {
+                       /*
+                        * These count the entries the stateless HEVC drivers
+                        * read from column_width_minus1[] / row_height_minus1[]
+                        * and use as tile-loop bounds.
+                        */
+                       if (p_hevc_pps->num_tile_columns_minus1 >=
+                           ARRAY_SIZE(p_hevc_pps->column_width_minus1))
+                               return -EINVAL;
+                       if (p_hevc_pps->num_tile_rows_minus1 >=
+                           ARRAY_SIZE(p_hevc_pps->row_height_minus1))
+                               return -EINVAL;
                }
 
                if (p_hevc_pps->flags &
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to