From: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
To: "Cen Zhang (Microsoft)" <blbllhy@gmail.com>
Cc: mchehab@kernel.org, hverkuil@kernel.org, kees@kernel.org,
rongqianfeng@vivo.com, axboe@kernel.dk,
linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
AutonomousCodeSecurity@microsoft.com,
tgopinath@linux.microsoft.com, kys@microsoft.com
Subject: Re: [PATCH] media: dvb-core: add upper bound check in DMX_SET_BUFFER_SIZE ioctl
Date: Wed, 29 Jul 2026 08:44:31 +0200 [thread overview]
Message-ID: <20260729084431.30e0fee8@foz.lan> (raw)
In-Reply-To: <20260729083026.0e26efff@foz.lan>
On Wed, 29 Jul 2026 08:30:26 +0200
Mauro Carvalho Chehab <mchehab+huawei@kernel.org> wrote:
> On Wed, 22 Jul 2026 15:37:19 -0400
> "Cen Zhang (Microsoft)" <blbllhy@gmail.com> wrote:
>
> > dvb_dvr_set_buffer_size() and dvb_dmxdev_set_buffer_size() pass the
> > user-supplied size argument directly to vmalloc() without any upper
> > bound check. This allows excessive kernel memory allocation via the
> > DMX_SET_BUFFER_SIZE ioctl, which can lead to system-wide OOM conditions.
> >
> > Kernel panic - not syncing: System is deadlocked on memory
> >
> > Call Trace:
> > out_of_memory+0x12fd/0x1370
> > __alloc_frozen_pages_noprof+0x2620/0x2fa0
> > __vmalloc_node_range_noprof+0x7fa/0x1490
> > dvb_dvr_do_ioctl+0x11e/0x260 (drivers/media/dvb-core/dmxdev.c:296)
> > dvb_usercopy+0x15b/0x360
> >
> > Fix by cap both functions at 64 MB and return -EINVAL for oversized
> > requests.
> >
> > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> > Fixes: a095be4b030c ("V4L/DVB (7659): dvb-core: Implement DMX_SET_BUFFER_SIZE for dvr")
> > Reported-by: AutonomousCodeSecurity@microsoft.com
> > Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
> > ---
> > drivers/media/dvb-core/dmxdev.c | 7 +++++++
> > 1 file changed, 7 insertions(+)
> >
> > diff --git a/drivers/media/dvb-core/dmxdev.c b/drivers/media/dvb-core/dmxdev.c
> > index 3c8bc75e4d6c..b4dc87945be1 100644
> > --- a/drivers/media/dvb-core/dmxdev.c
> > +++ b/drivers/media/dvb-core/dmxdev.c
> > @@ -20,6 +20,9 @@
> > #include <media/dmxdev.h>
> > #include <media/dvb_vb2.h>
> >
> > +/* 64 MB upper bound for DVB ring buffer allocations */
> > +#define DVB_BUFFER_SIZE_MAX (64 * 1024 * 1024)
>
> Having a limit is good, but why 64MB?
>
> Can you provide me more details about the test scenario: e.g. with
> what TV standards had you test it, and such.
Forgot to mention, but instead of returning -EINVAL, probably the best
would be to setup the ringbuffer size to the maximum value, as
otherwise this would break existing apps.
Btw, what apps did you use to test it? Had you check what's the current
limit on what apps?
Regards,
Mauro
prev parent reply other threads:[~2026-07-29 6:44 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 19:37 [PATCH] media: dvb-core: add upper bound check in DMX_SET_BUFFER_SIZE ioctl Cen Zhang (Microsoft)
2026-07-29 6:30 ` Mauro Carvalho Chehab
2026-07-29 6:44 ` Mauro Carvalho Chehab [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729084431.30e0fee8@foz.lan \
--to=mchehab+huawei@kernel.org \
--cc=AutonomousCodeSecurity@microsoft.com \
--cc=axboe@kernel.dk \
--cc=blbllhy@gmail.com \
--cc=hverkuil@kernel.org \
--cc=kees@kernel.org \
--cc=kys@microsoft.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=rongqianfeng@vivo.com \
--cc=tgopinath@linux.microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.