On Tue Jun 16 22:18:59 2026 -0400, Michael Bommarito wrote:
> The stateless AV1 decoders use tile_info.tile_cols and tile_rows as loop
> bounds and as indices into the mi_*_starts[] and *_in_sbs_minus_1[]
> arrays, as the divisor for context_update_tile_id, and their product
> bounds the per-tile descriptor buffers, but std_validate_compound() does
> not bound these u8 fields. Reject a V4L2_CTRL_TYPE_AV1_FRAME whose
> tile_cols or tile_rows exceeds V4L2_AV1_MAX_TILE_COLS / _ROWS, or whose
> product exceeds V4L2_AV1_MAX_TILE_COUNT. A zero tile count is left to the
> consuming driver so the zero-initialised control that existing userspace
> submits is still accepted.
> 
> Fixes: 9de30f579980 ("media: Add AV1 uAPI")
> Assisted-by: Claude:claude-opus-4-8
> Cc: [email protected]
> Signed-off-by: Michael Bommarito <[email protected]>
> Reviewed-by: Benjamin Gaignard <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/v4l2-core/v4l2-ctrls-core.c | 20 ++++++++++++++++++++
 1 file changed, 20 insertions(+)

---

diff --git a/drivers/media/v4l2-core/v4l2-ctrls-core.c 
b/drivers/media/v4l2-core/v4l2-ctrls-core.c
index 9b6121a3a2d2..648b88c868bc 100644
--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
+++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
@@ -793,10 +793,30 @@ static int validate_av1_film_grain(struct 
v4l2_ctrl_av1_film_grain *fg)
        return 0;
 }
 
+static int validate_av1_tile_info(struct v4l2_av1_tile_info *t)
+{
+       /*
+        * tile_cols and tile_rows index the per-tile descriptor arrays and
+        * bound the tile loops in the stateless AV1 drivers; the product
+        * bounds the total tile descriptor count.
+        */
+       if (t->tile_cols > V4L2_AV1_MAX_TILE_COLS ||
+           t->tile_rows > V4L2_AV1_MAX_TILE_ROWS)
+               return -EINVAL;
+
+       if ((u32)t->tile_cols * t->tile_rows > V4L2_AV1_MAX_TILE_COUNT)
+               return -EINVAL;
+
+       return 0;
+}
+
 static int validate_av1_frame(struct v4l2_ctrl_av1_frame *f)
 {
        int ret = 0;
 
+       ret = validate_av1_tile_info(&f->tile_info);
+       if (ret)
+               return ret;
        ret = validate_av1_quantization(&f->quantization);
        if (ret)
                return ret;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to