On Tue Sep 8 15:27:21 2026 +0800, Junrui Luo wrote:
> The stateful decoder leaks uninitialized kernel heap memory to userspace.
> A process that can open the decoder video node gets it back in the CAPTURE
> buffers it dequeues.
> 
> The reference frame and the compressed frame buffer are allocated with
> kvmalloc() in vicodec_start_streaming(), and the decoder can read them
> before they have been written. The first frame is allowed to be a P-frame,
> in which case it is decoded against a reference frame that was never
> produced, and the padding rows below the visible area are never written
> for any frame.
> 
> Use kvzalloc() for both allocations.
> 
> Fixes: 256bf813ba39 ("media: vicodec: add the virtual codec driver")
> Reported-by: Yuhao Jiang <[email protected]>
> Assisted-by: Claude:claude-opus-5
> Cc: [email protected]
> Signed-off-by: Junrui Luo <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/test-drivers/vicodec/vicodec-core.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/test-drivers/vicodec/vicodec-core.c 
b/drivers/media/test-drivers/vicodec/vicodec-core.c
index 25ec3a43fc71..7ea024b14f0e 100644
--- a/drivers/media/test-drivers/vicodec/vicodec-core.c
+++ b/drivers/media/test-drivers/vicodec/vicodec-core.c
@@ -1605,9 +1605,9 @@ static int vicodec_start_streaming(struct vb2_queue *q,
        }
        state->ref_stride = q_data->coded_width * info->luma_alpha_step;
 
-       state->ref_frame.buf = kvmalloc(total_planes_size, GFP_KERNEL);
+       state->ref_frame.buf = kvzalloc(total_planes_size, GFP_KERNEL);
        state->ref_frame.luma = state->ref_frame.buf;
-       new_comp_frame = kvmalloc(ctx->comp_max_size, GFP_KERNEL);
+       new_comp_frame = kvzalloc(ctx->comp_max_size, GFP_KERNEL);
 
        if (!state->ref_frame.luma || !new_comp_frame) {
                kvfree(state->ref_frame.luma);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to