[PATCH v2 3/3] media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow

Nicolas Dufresne nicolas.dufresne at collabora.com
Wed Jul 15 15:45:21 PDT 2026


Le mercredi 27 mai 2026 à 15:47 -0400, Michael Bommarito a écrit :
> st_ref_pic_set_prediction() computes the reference RPS index as
> st_rps_idx - (delta_idx_minus1 + 1) per HEVC spec equation 7-59.
> Both operands are u8, so when delta_idx_minus1 + 1 exceeds the
> current index the subtraction wraps and the subsequent array access
> at calculated_rps_st_sets[ref_rps_idx] reads far out of bounds.
> 
> A userspace V4L2 client that can open the RKVDEC m2m decoder can
> submit an EXT_SPS_ST_RPS control with INTER_REF_PIC_SET_PRED set
> and delta_idx_minus1 crafted to trigger the underflow.
> 
> Reject the entry early when the reference index would underflow.
> 
> Fixes: c9a59dc2acc7 ("media: rkvdec: Add HEVC support for the VDPU381 variant")
> Cc: stable at vger.kernel.org
> Suggested-by: Detlev Casanova <detlev.casanova at collabora.com>
> Assisted-by: Claude:claude-opus-4-7
> Signed-off-by: Michael Bommarito <michael.bommarito at gmail.com>

Reviewed-by: Nicolas Dufresne <nicolas.dufresne at collabora.com>

> ---
>  drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
> index 3119f3bc9f98b..898d1ce74f38a 100644
> --- a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
> +++ b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
> @@ -268,6 +268,9 @@ static void st_ref_pic_set_prediction(struct rkvdec_hevc_run *run, int idx,
>  	int i, j;
>  	int dPoc;
>  
> +	if ((unsigned int)rps_data->delta_idx_minus1 + 1 > idx)
> +		return;
> +
>  	ref_rps_idx = st_rps_idx - (rps_data->delta_idx_minus1 + 1); /* 7-59 */
>  	delta_rps = (1 - 2 * rps_data->delta_rps_sign) *
>  		   (rps_data->abs_delta_rps_minus1 + 1); /* 7-60 */
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 228 bytes
Desc: This is a digitally signed message part
URL: <http://lists.infradead.org/pipermail/linux-rockchip/attachments/20260715/dcb4e762/attachment.sig>


More information about the Linux-rockchip mailing list