RE: [PATCH 1/4] drm/amdgpu: Reject UVD message with dimensions above 4096

"Dong, Ruijing" <[email protected]>
Newsgroups org.freedesktop.lists.amd-gfx
Message-ID <LV2PR12MB5773A2D5DC05E226EB513F6095DE2@LV2PR12MB5773.namprd12.prod.outlook.com>
AMD General

This series is

Reviewed-by: Ruijing Dong <[email protected]>

Thanks,
Ruijing

-----Original Message-----
From: amd-gfx <[email protected]> On Behalf Of David Rosca
Sent: Thursday, July 30, 2026 1:02 PM
To: [email protected]
Cc: Rosca, David <[email protected]>
Subject: [PATCH 1/4] drm/amdgpu: Reject UVD message with dimensions above 4096

Fixes potential overflow in DPB size calculations.

Signed-off-by: David Rosca <[email protected]>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
index e8b0c62f72be..63561d1d7963 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
@@ -655,8 +655,8 @@ static int amdgpu_uvd_cs_msg_decode(struct amdgpu_device *adev, uint32_t *msg,
        unsigned int image_size, tmp, min_dpb_size, num_dpb_buffer;
        unsigned int min_ctx_size = ~0;

-       /* Reject invalid dimensions to prevent division by zero */
-       if (width < 16 || height < 16) {
+       /* Reject invalid dimensions */
+       if (width < 16 || height < 16 || width > 4096 || height > 4096) {
                dev_WARN_ONCE(adev->dev, 1,
                              "Invalid UVD decoding dimensions (%dx%d)!\n",
                              width, height);
--
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.