On Tue Sep 8 15:27:21 2026 +0800, Junrui Luo wrote:
> The stateful decoder leaks uninitialized kernel heap memory to userspace.
> A process that can open the decoder video node gets it back in the CAPTURE
> buffers it dequeues.
>
> The reference frame and the compressed frame buffer are allocated with
> kvmalloc() in vicodec_start_streaming(), and the decoder can read them
> before they have been written. The first frame is allowed to be a P-frame,
> in which case it is decoded against a reference frame that was never
> produced, and the padding rows below the visible area are never written
> for any frame.
>
> Use kvzalloc() for both allocations.
>
> Fixes: 256bf813ba39 ("media: vicodec: add the virtual codec driver")
> Reported-by: Yuhao Jiang <[email protected]>
> Assisted-by: Claude:claude-opus-5
> Cc: [email protected]
> Signed-off-by: Junrui Luo <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/test-drivers/vicodec/vicodec-core.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
---
diff --git a/drivers/media/test-drivers/vicodec/vicodec-core.c
b/drivers/media/test-drivers/vicodec/vicodec-core.c
index 25ec3a43fc71..7ea024b14f0e 100644
--- a/drivers/media/test-drivers/vicodec/vicodec-core.c
+++ b/drivers/media/test-drivers/vicodec/vicodec-core.c
@@ -1605,9 +1605,9 @@ static int vicodec_start_streaming(struct vb2_queue *q,
}
state->ref_stride = q_data->coded_width * info->luma_alpha_step;
- state->ref_frame.buf = kvmalloc(total_planes_size, GFP_KERNEL);
+ state->ref_frame.buf = kvzalloc(total_planes_size, GFP_KERNEL);
state->ref_frame.luma = state->ref_frame.buf;
- new_comp_frame = kvmalloc(ctx->comp_max_size, GFP_KERNEL);
+ new_comp_frame = kvzalloc(ctx->comp_max_size, GFP_KERNEL);
if (!state->ref_frame.luma || !new_comp_frame) {
kvfree(state->ref_frame.luma);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]