From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 14CDF39D6F6 for ; Fri, 21 Aug 2026 21:27:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787347672; cv=none; b=CDsRO5CdA2aGNjK1hpeSnyIZ1PnbkikZutDKrYDLS9MRXMfPSJFtA8+tFyioA1+bH2rz9NbjKITdoMfaRyQdnfKNletGFEYV5pMNmZW68oeCMclbZxAQlRMAuNJIosk+IO6LTU8SQmGyC0hB+XdqA5xRtezxMqawzrBujQaLyNQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787347672; c=relaxed/simple; bh=iW5v4cPa+jY4BUhIVqaq+GenRgtpAr+S8n1Qt7BhIyc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=s0IbkDxhPtTbOITeuD2YL3NPC835d/YucXiMGCb+YPFu+gZ2nvLW/uafK/hcC0D6220W2RhkaQ0Y3VF7MD7Is75OkY9QdbpjCKQjKxA1jvyU3Q9bxh3iLy7wvBORGkJzRDY/48RIoCsrWJ/f9Z/JIJXWQDHAZjnvQrORaSM1bTM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=W2HLMES4; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="W2HLMES4" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-4921eed3fa2so13988295e9.0 for ; Fri, 21 Aug 2026 14:27:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787347669; x=1787952469; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=cUXEtXgpHp+az+q2AbTUR3kHFspQTU4Js/4VE5CWhoE=; b=W2HLMES4gWANIVB20ZDK8ATmZfmA7qo6wkl3EqlTXnODAIH0Q9awyigSw3joOUk0t/ curZpS3CrBNvfNUkxdFmRn05wk9sJebKHaYP6dZ3W0l//2UqWK3KdMAb2/atbRYJOZgc yDyVzms2c8kDbJPTlJNx2V8aILEHoe/5jCLlMhnTOZLD5n2iqyGRpLupunuZuWCUrYDQ /Q0btAjKAycwkL04y27vCzAVwMxlqdWO1loSs8wz8q6DyBY8RAor/eVOUdIZlhN2U62+ XOw1CzA5nXkYls1tJRtb+ZYGeUq/7IA24Lk1Kn7AiZFfo+SQN4TVfA9buu2dzyfedUNH SzsA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787347669; x=1787952469; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cUXEtXgpHp+az+q2AbTUR3kHFspQTU4Js/4VE5CWhoE=; b=hEOopMC1P0evik2YDSwlSmyz37CIVeMJ4Z7EjBMvxiktHNqTwJtSS3TGpS9yDAXuC+ mnQqk/RJFg+1yW1uZ+rYCSjiYYaqn/tgeaDLvLBQV21buItsxWk62FH+gpjcWnbqWekV zr+qMsx9YhJS6sqLYRDuj2Vgrjp8x/Di3cQ0AHDx42yylIQff9VhH1O4kZ3KVGK8KplJ FBJID6RIAdQ/c5Q5CHxXZpehrzFkz1OUwdd4pYFimRswHUDOOD5nwu2r5kVaIsHmzNKS 0itZgHIwQhYn10NaXyZYyv2QMPNH11sd27XUMCiqRUxtXtNbwIiiJlxLss24LET5/tII x0Vg== X-Forwarded-Encrypted: i=1; AHgh+RroWThY1GqcWk7fkGK8dbG89O2LWsGqBQCMmkU4WWhmyiWue9QM23ricuRMCQnbICGG/Itk9DY0/yQzyiw=@vger.kernel.org X-Gm-Message-State: AFuF++mhCWTlfTL9sbC6aWAmUwtJVGrZh9r/vz9aN5MLNt0EsFlSbi6f mxtx6lm9ABXyxWOR5aXmkbDYUjX0W8S8apN4UGt5R6eisqSft3Nmehnd X-Gm-Gg: AR+sD10G7lUkC35pb+xMhD5SOEHL30le/8xkAuCMvd4giUsA2TIlDL5SzQoQzsi0gjk Jx01gPzjU9pLjjpG6s3WWsA17BRv9jK3xDRr25Q7XBZxj1KKSmUirwRNAIXGmVQXJC0S1lqWtp2 J91FE4lmDIghspJdwmq8XOht1ijJoqHTxobyKbBG6b3rd9MNZWIcVXmqSNtVA8td0gBPdy1k4Ob 62SL/M9haltwL649wGYh6rH9CQqHi4X/IVL8gUVxdm0ZXVn7qQq+Hl909dcEa9pXafjUVggwxU9 Z9Jznmm6+Lb1cPJ//W7pAJ9qzWTSXzE5pyar0xyGIylg4I+nVUscgdU+zkkkc4bq5H66drPGrp0 avvBUL3jOOWqaSpiV8pftwgYKtjro1RqV0vQcq2fqbNa3H3anSKm+/fZKKv2n9pQyylL6DeTp3Z BE2xrUs84zrOeNmrXaSgl5lXsHOgcxXL3efmzXLbATvacghjRtS1pPtPrUDeazJQByUkiirYeXw 5lYl3TclOBXRH5oYpN0kc56uzUjm4bP1UPMWL4UHt5lY1Ok X-Received: by 2002:a05:600c:5486:b0:499:a277:e8c8 with SMTP id 5b1f17b1804b1-499b8464cb8mr119003925e9.13.1787347669140; Fri, 21 Aug 2026 14:27:49 -0700 (PDT) Received: from dohko.chello.ie (188-141-5-72.dynamic.upc.ie. [188.141.5.72]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499b9a89572sm30762815e9.0.2026.08.21.14.27.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 14:27:47 -0700 (PDT) From: David Carlier To: Keke Li Cc: Jacopo Mondi , Mauro Carvalho Chehab , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] media: amlogic-c3: Fix out-of-bounds read of metering zone coordinates Date: Fri, 21 Aug 2026 22:27:46 +0100 Message-ID: <20260821212746.214853-1-devnexen@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The AWB, AE and AF coordinate loops bound themselves by max(horiz_zones_num, vert_zones_num) + 1. Both counts are u8 values taken verbatim from userspace, so the bound reaches 256 while the coordinate arrays hold 18 entries (AE, AF) or 33 (AWB). An AF block placed last in a full payload reads 474 bytes past the parameters buffer. Clamp the point count to the array size, as the zone weight loops already do. Cc: stable@vger.kernel.org Signed-off-by: David Carlier --- drivers/media/platform/amlogic/c3/isp/c3-isp-params.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c b/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c index ae0777a20bda..f2396e2c6640 100644 --- a/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c +++ b/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c @@ -139,7 +139,8 @@ static void c3_isp_params_awb_cood(struct c3_isp_device *isp, unsigned int max_point_num; /* The number of points is one more than the number of edges */ - max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1; + max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1, + C3_ISP_AWB_MAX_PT_NUM); /* Set the index address to 0 position */ c3_isp_write(isp, ISP_AWB_IDX_ADDR, 0); @@ -258,7 +259,8 @@ static void c3_isp_params_ae_cood(struct c3_isp_device *isp, unsigned int max_point_num; /* The number of points is one more than the number of edges */ - max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1; + max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1, + C3_ISP_AE_MAX_PT_NUM); /* Set the index address to 0 position */ c3_isp_write(isp, ISP_AE_IDX_ADDR, 0); @@ -316,7 +318,8 @@ static void c3_isp_params_af_cood(struct c3_isp_device *isp, unsigned int max_point_num; /* The number of points is one more than the number of edges */ - max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1; + max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1, + C3_ISP_AF_MAX_PT_NUM); /* Set the index address to 0 position */ c3_isp_write(isp, ISP_AF_IDX_ADDR, 0); -- 2.55.0