[PATCH] media: vicodec: fix NULL deref on oversized frame
Junrui Luo via B4 Relay <[email protected]> Mon, 03 Aug 2026 15:29:36 +0800
| Newsgroups | org.kernel.vger.linux-media,org.kernel.feeds.b4-sent,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
From: Junrui Luo <[email protected]> job_ready() only honours the is_header_valid() verdict when ctx->comp_has_frame is set, and comp_has_frame is only set once comp_size reaches the full frame size. Since the copy is clamped to ctx->comp_max_size, a header advertising a larger size leaves comp_size stuck at comp_max_size, so comp_has_frame stays false and the failed validation is discarded. Control then falls into the resolution change branch, which calls update_capture_data_from_header(). That function re-derives info via info_from_header(), assigns it to q_dst->info and dereferences it as q_dst->info->sizeimage_mult, with no NULL check of its own. is_header_valid() does check that same info_from_header() result -- if (!info) return false which is precisely the false verdict job_ready() discarded above. info_from_header() returns NULL whenever the header flags resolve to no supported pixel format. Drop the comp_has_frame conjunct so an invalid header always bails out. The resolution change path is unaffected, as it is entered with a valid header. Oversized frames are then rejected by device_process(), which already returns -EINVAL when comp_frame_size exceeds comp_max_size. Fixes: 3b15f68e19c2 ("media: vicodec: Add support for resolution change event.") Reported-by: Yuhao Jiang <[email protected]> Cc: [email protected] Signed-off-by: Junrui Luo <[email protected]> --- drivers/media/test-drivers/vicodec/vicodec-core.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/media/test-drivers/vicodec/vicodec-core.c b/drivers/media/test-drivers/vicodec/vicodec-core.c index 318e8330f16a..dfc8dde4bad6 100644 --- a/drivers/media/test-drivers/vicodec/vicodec-core.c +++ b/drivers/media/test-drivers/vicodec/vicodec-core.c @@ -654,7 +654,7 @@ static int job_ready(void *priv) * if the header is invalid the device_run will just drop the frame * with an error */ - if (!is_header_valid(&ctx->state.header) && ctx->comp_has_frame) + if (!is_header_valid(&ctx->state.header)) return 1; flags = ntohl(ctx->state.header.flags); hdr_width_div = (flags & V4L2_FWHT_FL_CHROMA_FULL_WIDTH) ? 1 : 2; --- base-commit: 075b74841bd0065a3bda3440873c747938e69b68 change-id: 20260803-vicodec-fixes-f8313923e415 Best regards, -- Junrui Luo <[email protected]>