Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

media: mediatek: vcodec: Can't set dst buffer to done when lat decode error

Core thread will call v4l2_m2m_buf_done to set dst buffer done for
lat architecture. If lat call v4l2_m2m_buf_done_and_job_finish to
free dst buffer when lat decode error, core thread will access kernel
NULL pointer dereference, then crash.

Signed-off-by: Yunfei Dong <yunfei.dong@mediatek.com>
Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org>

authored by

Yunfei Dong and committed by
Mauro Carvalho Chehab
3568ecd3 d879f770

+1 -1
+1 -1
drivers/media/platform/mediatek/vcodec/mtk_vcodec_dec_stateless.c
··· 253 253 254 254 state = ret ? VB2_BUF_STATE_ERROR : VB2_BUF_STATE_DONE; 255 255 if (!IS_VDEC_LAT_ARCH(dev->vdec_pdata->hw_arch) || 256 - ctx->current_codec == V4L2_PIX_FMT_VP8_FRAME || ret) { 256 + ctx->current_codec == V4L2_PIX_FMT_VP8_FRAME) { 257 257 v4l2_m2m_buf_done_and_job_finish(dev->m2m_dev_dec, ctx->m2m_ctx, state); 258 258 if (src_buf_req) 259 259 v4l2_ctrl_request_complete(src_buf_req, &ctx->ctrl_hdl);