forked from rubenslte/android_kernel_samsung_msm8226
msm: vidc: Validate userspace buffer count
Makesure the number of buffers count is less than the maximum limit to avoid structure overflow errors. Change-Id: Icf3850de36325637ae43ac95f1c8f0f63e201d31 CRs-fixed: 563694 Signed-off-by: Pachika, Vikas Reddy <vpachi@codeaurora.org>
This commit is contained in:
committed by
Gerrit - the friendly Code Review server
parent
d1cf5e61cb
commit
82929c4ccf
@@ -1104,6 +1104,12 @@ static u32 vid_dec_set_h264_mv_buffers(struct video_client_ctx *client_ctx,
|
||||
vcd_h264_mv_buffer->pmem_fd = mv_data->pmem_fd;
|
||||
vcd_h264_mv_buffer->offset = mv_data->offset;
|
||||
|
||||
if (mv_data->count > MAX_MV_BUFFERS) {
|
||||
ERR("MV buffers maximum count reached, count = %d",
|
||||
mv_data->count);
|
||||
return false;
|
||||
}
|
||||
|
||||
if (!vcd_get_ion_status()) {
|
||||
pr_err("PMEM not available\n");
|
||||
return false;
|
||||
|
||||
@@ -20,6 +20,7 @@
|
||||
#define VIDC_MAX_NUM_CLIENTS 4
|
||||
#define MAX_VIDEO_NUM_OF_BUFF 100
|
||||
#define MAX_META_BUFFERS 32
|
||||
#define MAX_MV_BUFFERS 32
|
||||
|
||||
enum buffer_dir {
|
||||
BUFFER_TYPE_INPUT,
|
||||
|
||||
Reference in New Issue
Block a user