AMD General

Reviewed-by: Leo Liu <[email protected]>


> -----Original Message-----
> From: amd-gfx <[email protected]> On Behalf Of David
> Rosca
> Sent: Tuesday, August 11, 2026 5:07 AM
> To: [email protected]
> Cc: Rosca, David <[email protected]>
> Subject: [PATCH] drm/amdgpu: Reject UVD message with invalid number of h265
> refs
>
> Same change as for h264, avoids overflow later when calculating min dpb size.
>
> Signed-off-by: David Rosca <[email protected]>
> ---
>  drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c | 3 +++
>  1 file changed, 3 insertions(+)
>
> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> index e2d0f23d48aa..228a405a94c4 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> @@ -749,6 +749,9 @@ static int amdgpu_uvd_cs_msg_decode(struct
> amdgpu_device *adev, uint32_t *msg,
>               image_size = ALIGN(image_size, 256);
>
>               num_dpb_buffer = (le32_to_cpu(msg[59]) & 0xff) + 2;
> +             if (num_dpb_buffer > 17)
> +                     return -EINVAL;
> +
>               min_dpb_size = image_size * num_dpb_buffer;
>               min_ctx_size = ((width + 255) / 16) * ((height + 255) / 16)
>                                          * 16 * num_dpb_buffer + 52 * 1024;
> --
> 2.43.0

Reply via email to