On Tue Jun 16 22:18:58 2026 -0400, Michael Bommarito wrote:
> The stateless HEVC decoders read num_tile_columns_minus1 + 1 entries from
> column_width_minus1[] and num_tile_rows_minus1 + 1 from row_height_minus1[]
> and use them as tile-loop bounds, but std_validate_compound() does not
> bound these u8 counts. Reject a V4L2_CTRL_TYPE_HEVC_PPS with tiling
> enabled whose tile counts exceed the uAPI array capacity, mirroring the
> existing compound-control range checks.
>
> Fixes: 256fa3920874 ("media: v4l: Add definitions for HEVC stateless
> decoding")
> Assisted-by: Claude:claude-opus-4-8
> Cc: [email protected]
> Signed-off-by: Michael Bommarito <[email protected]>
> Reviewed-by: Benjamin Gaignard <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/v4l2-core/v4l2-ctrls-core.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
---
diff --git a/drivers/media/v4l2-core/v4l2-ctrls-core.c
b/drivers/media/v4l2-core/v4l2-ctrls-core.c
index 5b8a594fb9e2..9b6121a3a2d2 100644
--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
+++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
@@ -1253,6 +1253,18 @@ static int std_validate_compound(const struct v4l2_ctrl
*ctrl, u32 idx,
p_hevc_pps->flags &=
~V4L2_HEVC_PPS_FLAG_LOOP_FILTER_ACROSS_TILES_ENABLED;
+ } else {
+ /*
+ * These count the entries the stateless HEVC drivers
+ * read from column_width_minus1[] / row_height_minus1[]
+ * and use as tile-loop bounds.
+ */
+ if (p_hevc_pps->num_tile_columns_minus1 >=
+ ARRAY_SIZE(p_hevc_pps->column_width_minus1))
+ return -EINVAL;
+ if (p_hevc_pps->num_tile_rows_minus1 >=
+ ARRAY_SIZE(p_hevc_pps->row_height_minus1))
+ return -EINVAL;
}
if (p_hevc_pps->flags &
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]