[PATCH] amdgpu/vcn: vcn dec_msg integer overflow fix

"David (Ming Qiang) Wu" <[email protected]> Fri, 7 Aug 2026 15:41:31 -0400
Newsgroups org.freedesktop.lists.amd-gfx
Message-ID <[email protected]>
if supplied msg[2] in the header is too large (around
0x40000000 and above), 4 times of this unsigned 32 bit value
will overflow and the test could pass.

Widen it with uint64_t instead. Also drop the redundant
first check and make the check clear that 6 dwords of
header plus 4 dwords of each msg cannot exceed the overall
packet size in dwords.

Signed-off-by: David (Ming Qiang) Wu <[email protected]>
---
 drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c | 2 +-
 drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c b/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
index 81bba3ec2a93..06dcf736b15a 100644
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
@@ -1965,7 +1965,7 @@ static int vcn_v3_0_dec_msg(struct amdgpu_cs_parser *p, struct amdgpu_job *job,
 	num_buffers = msg[2];
 
 	/* Verify that all indices fit within the claimed length. Each index is 4 DWORDs */
-	if (num_buffers > len_dw || 6 + num_buffers * 4 > len_dw) {
+	if ((uint64_t)6 + (uint64_t)num_buffers * 4 > len_dw) {
 		DRM_ERROR("VCN message has too many buffers!\n");
 		r = -EINVAL;
 		goto out;
diff --git a/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c b/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
index 0cce78b205a8..7950a020f4e1 100644
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
@@ -1881,7 +1881,7 @@ static int vcn_v4_0_dec_msg(struct amdgpu_cs_parser *p, struct amdgpu_job *job,
 	num_buffers = msg[2];
 
 	/* Verify that all indices fit within the claimed length. Each index is 4 DWORDs */
-	if (num_buffers > len_dw || 6 + num_buffers * 4 > len_dw) {
+	if ((uint64_t)6 + (uint64_t)num_buffers * 4 > len_dw) {
 		DRM_ERROR("VCN message has too many buffers!\n");
 		r = -EINVAL;
 		goto out;
-- 
2.43.0