[PATCH V2] media: mediatek: jpeg: Fix potential array out-of-bounds in mtk_jpeg_queue_setup

499671216 at qq.com 499671216 at qq.com
Mon Jun 12 05:20:46 PDT 2023


From: yqsun1997 <yqsun1997 at gmail.com>

The variable *num_planes is provided by user.
The possible value of q_data->fmt->colplanes is 1-3,
The array access by index  can cause array out-of-bounds.
same as commit 8fbcf730

Signed-off-by: yqsun1997 <yqsun1997 at gmail.com>
---
 drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
index 0051f372a..3ccde524d 100644
--- a/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
+++ b/drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c
@@ -689,6 +689,8 @@ static int mtk_jpeg_queue_setup(struct vb2_queue *q,
 		return -EINVAL;
 
 	if (*num_planes) {
+		if (*num_planes != q_data->fmt->colplanes)
+			return -EINVAL;
 		for (i = 0; i < *num_planes; i++)
 			if (sizes[i] < q_data->pix_mp.plane_fmt[i].sizeimage)
 				return -EINVAL;
-- 
2.34.1




More information about the Linux-mediatek mailing list