RE: [PATCH] drm/amdgpu: Reject UVD message with invalid number of h265 refs

"Liu, Leo" <[email protected]>
Newsgroups org.freedesktop.lists.amd-gfx
Message-ID <CH3PR12MB757293F0BDBBD845406C0890E5DD2@CH3PR12MB7572.namprd12.prod.outlook.com>
AMD General

Reviewed-by: Leo Liu <[email protected]>


> -----Original Message-----
> From: amd-gfx <[email protected]> On Behalf Of David
> Rosca
> Sent: Tuesday, August 11, 2026 5:07 AM
> To: [email protected]
> Cc: Rosca, David <[email protected]>
> Subject: [PATCH] drm/amdgpu: Reject UVD message with invalid number of h265
> refs
>
> Same change as for h264, avoids overflow later when calculating min dpb size.
>
> Signed-off-by: David Rosca <[email protected]>
> ---
>  drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c | 3 +++
>  1 file changed, 3 insertions(+)
>
> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> index e2d0f23d48aa..228a405a94c4 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
> @@ -749,6 +749,9 @@ static int amdgpu_uvd_cs_msg_decode(struct
> amdgpu_device *adev, uint32_t *msg,
>               image_size = ALIGN(image_size, 256);
>
>               num_dpb_buffer = (le32_to_cpu(msg[59]) & 0xff) + 2;
> +             if (num_dpb_buffer > 17)
> +                     return -EINVAL;
> +
>               min_dpb_size = image_size * num_dpb_buffer;
>               min_ctx_size = ((width + 255) / 16) * ((height + 255) / 16)
>                                          * 16 * num_dpb_buffer + 52 * 1024;
> --
> 2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.