From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EE255347BA9 for ; Fri, 21 Aug 2026 21:28:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787347735; cv=none; b=Qq0u/3XWlDRSqACR+2BcGTi799INBTBkM5ZuojKYryRCDBXn2yO2TFTRVnu59ZHXS6SX2ais/amEh4N+v1jEai4UhZ6SfQkEwIqhaAPx4hpHfYq3I8ffcGpKhW/MukyOfwCKL1P3QwZQKh35uDgErUaQ9Db3W2mg43LvTFcUIc0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787347735; c=relaxed/simple; bh=iW5v4cPa+jY4BUhIVqaq+GenRgtpAr+S8n1Qt7BhIyc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=SuwjAqU7i27MdIymAkGoN5SEzP6W1kA2pf+FtZ9BEvpOODrd4Eckhh1fx+4nbFCs770ie5rjrIWla5VWcyDJEki0WZFou0fz0959cemtAOagLvJ+OSCvxoY76hdw9sxvufkQZsPYGFlamjTk09PffLbvVvLb4FjrPvWORWS0zF4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=j8fwmwSs; arc=none smtp.client-ip=209.85.128.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="j8fwmwSs" Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-499b57cf2f3so8953425e9.0 for ; Fri, 21 Aug 2026 14:28:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787347732; x=1787952532; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=cUXEtXgpHp+az+q2AbTUR3kHFspQTU4Js/4VE5CWhoE=; b=j8fwmwSspKKgt+d3r4IEs8E/CFFqDFvzQR1bnvW3n1rsYqkDF1SlBtGWPcsJhS3wBu P0AniAV+9t4I0O0PO14t9uLx7Gd6LNhG4le3rFJwiExaAuOEKitnw1PYrt/yOTXB4mRP I+oD8Q0TEutYKU3Ehsvraie8YUbkDfhO8oCdKSWgmZR0hcKHkYoloNvUtvVhBwd7YkG0 dJJnie2J+qwrgo3mwK9OA76ISRQa/BKX0O69RwWEnLo39zfJAK1HS2PJQdAI5iejO6Lm aXBQ6AVrlTqyck/vUgFC2SAPKNz4Q7TzWFL6YK4gHP3brJuoaUZhuMv1FcidoE+Ji9Ss tA9Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787347732; x=1787952532; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cUXEtXgpHp+az+q2AbTUR3kHFspQTU4Js/4VE5CWhoE=; b=H3KAN75BIHg/N0OVD9IyacYjZ2/MKyk42lebw1cdxKIEm+Qk5Cm1OsdoQYI0rZfkf3 jGJ7XbTQo4yG1EEvTr9q3lHFdevwPNBorLN/ZupklIwOiihRiga9GExg6vsU3IvzefBh G0jzd9Uqvt03a6gJ6yE0l/frZ0SrU3zCeR0uFraP+AMiXroG15QxqFEw/kDMB+th8N31 w2IIZX00qZWkQEqKBPwdlPnUK4vqVh+4xniJhqti9Xidf2zAhyK5661Lcz/DC8yL7+sp akzb0uZkww+tCEKianioQC05+nYfBBQ7rRuV6ZVlgKCR7UdUd56g5aueLNRs8Y3FQ+1n QJYw== X-Forwarded-Encrypted: i=1; AHgh+Rp/nnBv18qwBLa6mpsXwq+2wDUdXrt5WDBuTDWFEA8r3YBuAJZuetjGiq6sixwBOu3T00HNwlsl5SZYx5k=@vger.kernel.org X-Gm-Message-State: AFuF++knU9Ym0C0vC6piFbPyHv/T2YNr4OpYsRXzEJDEtKUNIT8sIodq FSh8RlZjk4fsSXLdSpjJ/dE1ysq+/2kybMht8bwxN1i0iibVDs4RNCCiLHjkug== X-Gm-Gg: AR+sD11yYuVR9c0AccGbY8kxutlTWcxZCVR85ugGecyQ5TeMqNUepAqLKNTFwNacZME YVre4L0Af1XkzE1tLqZdBtVzaw9ppTWAMCyb3hrkaffpcWQD8OiLPZZnhLxyolhAJSzkLe4MapG lZcoV8KSfJUiuvIY1LUOvuf4NW0LtagQRKtO3wygtEOzj6sY0tI8W3C9asWhIhZa0KVied7sCiI /28/HYgzsr29o+s0cPFheo+HlebXKkldz9t/pVdj/VVptmn/iQQpjclP26Q9XkkkDDkKOM6p5ZF /YfrGg4/uFXICCe1GI/MDYlajKjzrEJ+D62lZZuPZtdGXJ4YyBTcwicQxFbhZp1BSD+rsA+hAQ+ pQ6M0OphPrMU3OqxrmInAuCJL7pX3ZpT+kI4UZF1aNPwgXolAzAPFeAfrxAYz42ZMnh7mUqXSMT 6DjwFsCcDWBNfzqkjCbX6XDjnIbaJ8C1/SZTEI3GZPMARnyiWIR0aL1nq/cd9aYQ+8PLHaURt+n Z+cxUlZuzBk+AggctZq6/En+qmlgirwio+7Vb/qHja8fH8RXTpJaOvSMk4= X-Received: by 2002:a05:600c:78f:b0:493:e543:1dd9 with SMTP id 5b1f17b1804b1-499b071ce49mr167339025e9.9.1787347732215; Fri, 21 Aug 2026 14:28:52 -0700 (PDT) Received: from dohko.chello.ie (188-141-5-72.dynamic.upc.ie. [188.141.5.72]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482c9b78ebfsm147415f8f.12.2026.08.21.14.28.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 14:28:50 -0700 (PDT) From: David Carlier To: Keke Li Cc: Jacopo Mondi , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, David Carlier , stable@vger.kernel.org Subject: [PATCH] media: amlogic-c3: Fix out-of-bounds read of metering zone coordinates Date: Fri, 21 Aug 2026 22:28:48 +0100 Message-ID: <20260821212848.214982-1-devnexen@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The AWB, AE and AF coordinate loops bound themselves by max(horiz_zones_num, vert_zones_num) + 1. Both counts are u8 values taken verbatim from userspace, so the bound reaches 256 while the coordinate arrays hold 18 entries (AE, AF) or 33 (AWB). An AF block placed last in a full payload reads 474 bytes past the parameters buffer. Clamp the point count to the array size, as the zone weight loops already do. Cc: stable@vger.kernel.org Signed-off-by: David Carlier --- drivers/media/platform/amlogic/c3/isp/c3-isp-params.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c b/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c index ae0777a20bda..f2396e2c6640 100644 --- a/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c +++ b/drivers/media/platform/amlogic/c3/isp/c3-isp-params.c @@ -139,7 +139,8 @@ static void c3_isp_params_awb_cood(struct c3_isp_device *isp, unsigned int max_point_num; /* The number of points is one more than the number of edges */ - max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1; + max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1, + C3_ISP_AWB_MAX_PT_NUM); /* Set the index address to 0 position */ c3_isp_write(isp, ISP_AWB_IDX_ADDR, 0); @@ -258,7 +259,8 @@ static void c3_isp_params_ae_cood(struct c3_isp_device *isp, unsigned int max_point_num; /* The number of points is one more than the number of edges */ - max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1; + max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1, + C3_ISP_AE_MAX_PT_NUM); /* Set the index address to 0 position */ c3_isp_write(isp, ISP_AE_IDX_ADDR, 0); @@ -316,7 +318,8 @@ static void c3_isp_params_af_cood(struct c3_isp_device *isp, unsigned int max_point_num; /* The number of points is one more than the number of edges */ - max_point_num = max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1; + max_point_num = min(max(cfg->horiz_zones_num, cfg->vert_zones_num) + 1, + C3_ISP_AF_MAX_PT_NUM); /* Set the index address to 0 position */ c3_isp_write(isp, ISP_AF_IDX_ADDR, 0); -- 2.55.0