From: David Carlier <devnexen@gmail.com>
To: Keke Li <keke.li@amlogic.com>
Cc: Jacopo Mondi <jacopo.mondi@ideasonboard.com>,
linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
David Carlier <devnexen@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH] media: amlogic-c3: Fix out-of-bounds read of metering zone coordinates
Date: Fri, 21 Aug 2026 22:28:48 +0100 [thread overview]
Message-ID: <20260821212848.214982-1-devnexen@gmail.com> (raw)
The AWB, AE and AF coordinate loops bound themselves by
max(horiz_zones_num, vert_zones_num) + 1. Both counts are u8 values
taken verbatim from userspace, so the bound reaches 256 while the
coordinate arrays hold 18 entries (AE, AF) or 33 (AWB). An AF block
placed last in a full payload reads 474 bytes past the parameters
buffer.
Clamp the point count to the array size, as the zone weight loops
already do.
Cc: stable@vger.kernel.org
Signed-off-by: David Carlier <devnexen@gmail.com>
---
drivers/media/platform/amlogic/c3/isp/c3-isp-params.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c b/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c
index ae0777a20bda..f2396e2c6640 100644
--- a/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c
+++ b/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c
@@ -139,7 +139,8 @@ static void c3_isp_params_awb_cood(struct c3_isp_device *isp,
unsigned int max_point_num;
/* The number of points is one more than the number of edges */
- max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1;
+ max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1,
+ C3_ISP_AWB_MAX_PT_NUM);
/* Set the index address to 0 position */
c3_isp_write(isp, ISP_AWB_IDX_ADDR, 0);
@@ -258,7 +259,8 @@ static void c3_isp_params_ae_cood(struct c3_isp_device *isp,
unsigned int max_point_num;
/* The number of points is one more than the number of edges */
- max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1;
+ max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1,
+ C3_ISP_AE_MAX_PT_NUM);
/* Set the index address to 0 position */
c3_isp_write(isp, ISP_AE_IDX_ADDR, 0);
@@ -316,7 +318,8 @@ static void c3_isp_params_af_cood(struct c3_isp_device *isp,
unsigned int max_point_num;
/* The number of points is one more than the number of edges */
- max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1;
+ max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1,
+ C3_ISP_AF_MAX_PT_NUM);
/* Set the index address to 0 position */
c3_isp_write(isp, ISP_AF_IDX_ADDR, 0);
--
2.55.0
next reply other threads:[~2026-08-21 21:28 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 21:28 David Carlier [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-08-21 21:27 [PATCH] media: amlogic-c3: Fix out-of-bounds read of metering zone coordinates David Carlier
2026-08-21 21:27 David Carlier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260821212848.214982-1-devnexen@gmail.com \
--to=devnexen@gmail.com \
--cc=jacopo.mondi@ideasonboard.com \
--cc=keke.li@amlogic.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox