AMD General Reviewed-by: Leo Liu <[email protected]>
> -----Original Message----- > From: amd-gfx <[email protected]> On Behalf Of David > Rosca > Sent: Tuesday, August 11, 2026 5:07 AM > To: [email protected] > Cc: Rosca, David <[email protected]> > Subject: [PATCH] drm/amdgpu: Reject UVD message with invalid number of h265 > refs > > Same change as for h264, avoids overflow later when calculating min dpb size. > > Signed-off-by: David Rosca <[email protected]> > --- > drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c > b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c > index e2d0f23d48aa..228a405a94c4 100644 > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c > @@ -749,6 +749,9 @@ static int amdgpu_uvd_cs_msg_decode(struct > amdgpu_device *adev, uint32_t *msg, > image_size = ALIGN(image_size, 256); > > num_dpb_buffer = (le32_to_cpu(msg[59]) & 0xff) + 2; > + if (num_dpb_buffer > 17) > + return -EINVAL; > + > min_dpb_size = image_size * num_dpb_buffer; > min_ctx_size = ((width + 255) / 16) * ((height + 255) / 16) > * 16 * num_dpb_buffer + 52 * 1024; > -- > 2.43.0
