| From 0768a9dd809ef52440b5df7dce5a1c1c7e97abbd Mon Sep 17 00:00:00 2001 |
| From: Vikash Garodia <quic_vgarodia@quicinc.com> |
| Date: Thu, 10 Aug 2023 07:55:04 +0530 |
| Subject: media: venus: hfi_parser: Add check to keep the number of codecs within range |
| |
| From: Vikash Garodia <quic_vgarodia@quicinc.com> |
| |
| commit 0768a9dd809ef52440b5df7dce5a1c1c7e97abbd upstream. |
| |
| Supported codec bitmask is populated from the payload from venus firmware. |
| There is a possible case when all the bits in the codec bitmask is set. In |
| such case, core cap for decoder is filled and MAX_CODEC_NUM is utilized. |
| Now while filling the caps for encoder, it can lead to access the caps |
| array beyong 32 index. Hence leading to OOB write. |
| The fix counts the supported encoder and decoder. If the count is more than |
| max, then it skips accessing the caps. |
| |
| Cc: stable@vger.kernel.org |
| Fixes: 1a73374a04e5 ("media: venus: hfi_parser: add common capability parser") |
| Signed-off-by: Vikash Garodia <quic_vgarodia@quicinc.com> |
| Signed-off-by: Stanimir Varbanov <stanimir.k.varbanov@gmail.com> |
| Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/media/platform/qcom/venus/hfi_parser.c | 3 +++ |
| 1 file changed, 3 insertions(+) |
| |
| --- a/drivers/media/platform/qcom/venus/hfi_parser.c |
| +++ b/drivers/media/platform/qcom/venus/hfi_parser.c |
| @@ -19,6 +19,9 @@ static void init_codecs(struct venus_cor |
| struct hfi_plat_caps *caps = core->caps, *cap; |
| unsigned long bit; |
| |
| + if (hweight_long(core->dec_codecs) + hweight_long(core->enc_codecs) > MAX_CODEC_NUM) |
| + return; |
| + |
| for_each_set_bit(bit, &core->dec_codecs, MAX_CODEC_NUM) { |
| cap = &caps[core->codecs_count++]; |
| cap->codec = BIT(bit); |