mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
drm/amdgpu: fix division by zero with invalid uvd dimensions
commit0c01c811beupstream. When width or height is less than 16, width_in_mb or height_in_mb becomes 0, leading to fs_in_mb being 0. This causes a division by zero when calculating num_dpb_buffer in H264 and H264 Perf decode paths. Add validation to reject frames with width < 16 or height < 16 before performing any calculations that depend on these values. V2: Format change - move up all vaiable definitions. V3: Use warn_once to avoid spam. Signed-off-by: Boyuan Zhang <boyuan.zhang@amd.com> Reviewed-by: Leo Liu <leo.liu@amd.com> Reviewed-by: Alex Deucher <alexander.deucher@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit3e41d26c70) Cc: stable@vger.kernel.org Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
8c6d84a548
commit
ffb33d466a
@@ -654,6 +654,14 @@ static int amdgpu_uvd_cs_msg_decode(struct amdgpu_device *adev, uint32_t *msg,
|
||||
unsigned int image_size, tmp, min_dpb_size, num_dpb_buffer;
|
||||
unsigned int min_ctx_size = ~0;
|
||||
|
||||
/* Reject invalid dimensions to prevent division by zero */
|
||||
if (width < 16 || height < 16) {
|
||||
dev_WARN_ONCE(adev->dev, 1,
|
||||
"Invalid UVD decoding dimensions (%dx%d)!\n",
|
||||
width, height);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
image_size = width * height;
|
||||
image_size += image_size / 2;
|
||||
image_size = ALIGN(image_size, 1024);
|
||||
|
||||
Reference in New Issue
Block a user