Fixes potential overflow in DPB size calculations.

Signed-off-by: David Rosca <[email protected]>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c 
b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
index e8b0c62f72be..63561d1d7963 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
@@ -655,8 +655,8 @@ static int amdgpu_uvd_cs_msg_decode(struct amdgpu_device 
*adev, uint32_t *msg,
        unsigned int image_size, tmp, min_dpb_size, num_dpb_buffer;
        unsigned int min_ctx_size = ~0;
 
-       /* Reject invalid dimensions to prevent division by zero */
-       if (width < 16 || height < 16) {
+       /* Reject invalid dimensions */
+       if (width < 16 || height < 16 || width > 4096 || height > 4096) {
                dev_WARN_ONCE(adev->dev, 1,
                              "Invalid UVD decoding dimensions (%dx%d)!\n",
                              width, height);
-- 
2.43.0

Reply via email to