From: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
To: "Cen Zhang (Microsoft)" <blbllhy@gmail.com>
Cc: mchehab@kernel.org, hverkuil@kernel.org, kees@kernel.org,
rongqianfeng@vivo.com, axboe@kernel.dk,
linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
AutonomousCodeSecurity@microsoft.com,
tgopinath@linux.microsoft.com, kys@microsoft.com
Subject: Re: [PATCH] media: dvb-core: add upper bound check in DMX_SET_BUFFER_SIZE ioctl
Date: Wed, 29 Jul 2026 08:30:26 +0200 [thread overview]
Message-ID: <20260729083026.0e26efff@foz.lan> (raw)
In-Reply-To: <20260722193719.81157-1-blbllhy@gmail.com>
On Wed, 22 Jul 2026 15:37:19 -0400
"Cen Zhang (Microsoft)" <blbllhy@gmail.com> wrote:
> dvb_dvr_set_buffer_size() and dvb_dmxdev_set_buffer_size() pass the
> user-supplied size argument directly to vmalloc() without any upper
> bound check. This allows excessive kernel memory allocation via the
> DMX_SET_BUFFER_SIZE ioctl, which can lead to system-wide OOM conditions.
>
> Kernel panic - not syncing: System is deadlocked on memory
>
> Call Trace:
> out_of_memory+0x12fd/0x1370
> __alloc_frozen_pages_noprof+0x2620/0x2fa0
> __vmalloc_node_range_noprof+0x7fa/0x1490
> dvb_dvr_do_ioctl+0x11e/0x260 (drivers/media/dvb-core/dmxdev.c:296)
> dvb_usercopy+0x15b/0x360
>
> Fix by cap both functions at 64 MB and return -EINVAL for oversized
> requests.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Fixes: a095be4b030c ("V4L/DVB (7659): dvb-core: Implement DMX_SET_BUFFER_SIZE for dvr")
> Reported-by: AutonomousCodeSecurity@microsoft.com
> Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
> ---
> drivers/media/dvb-core/dmxdev.c | 7 +++++++
> 1 file changed, 7 insertions(+)
>
> diff --git a/drivers/media/dvb-core/dmxdev.c b/drivers/media/dvb-core/dmxdev.c
> index 3c8bc75e4d6c..b4dc87945be1 100644
> --- a/drivers/media/dvb-core/dmxdev.c
> +++ b/drivers/media/dvb-core/dmxdev.c
> @@ -20,6 +20,9 @@
> #include <media/dmxdev.h>
> #include <media/dvb_vb2.h>
>
> +/* 64 MB upper bound for DVB ring buffer allocations */
> +#define DVB_BUFFER_SIZE_MAX (64 * 1024 * 1024)
Having a limit is good, but why 64MB?
Can you provide me more details about the test scenario: e.g. with
what TV standards had you test it, and such.
Regards,
Mauro
Thanks,
Mauro
next prev parent reply other threads:[~2026-07-29 6:30 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 19:37 [PATCH] media: dvb-core: add upper bound check in DMX_SET_BUFFER_SIZE ioctl Cen Zhang (Microsoft)
2026-07-29 6:30 ` Mauro Carvalho Chehab [this message]
2026-07-29 6:44 ` Mauro Carvalho Chehab
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260729083026.0e26efff@foz.lan \
--to=mchehab+huawei@kernel.org \
--cc=AutonomousCodeSecurity@microsoft.com \
--cc=axboe@kernel.dk \
--cc=blbllhy@gmail.com \
--cc=hverkuil@kernel.org \
--cc=kees@kernel.org \
--cc=kys@microsoft.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=rongqianfeng@vivo.com \
--cc=tgopinath@linux.microsoft.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox