[FFmpeg-devel,PR] Prevent a buffer overread due to the Iris driver (a V4L2 backend) sending back the size of its padded memory buffer (PR #24742)

Message ID 20260927195650.AC6E72FF9E@ffbox0-bg.ffmpeg.org
State New
Headers
Series [FFmpeg-devel,PR] Prevent a buffer overread due to the Iris driver (a V4L2 backend) sending back the size of its padded memory buffer (PR #24742) |

Commit Message

t-boiko Sept. 27, 2026, 7:56 p.m. UTC
PR #24742 opened by trustytrojan
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24742
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24742.patch

This occurs when sending 1280x720 frames to the `h264_v4l2m2m` encoder. When running the following command:

```
ffmpeg -v debug -f lavfi -i testsrc=1280x720:d=1:rate=30 -pix_fmt nv12 -c:v h264_v4l2m2m -f null -
```

you will find this line in the debug output:

```
[h264_v4l2m2m @ 0xb243cd1f4d30] output: NV12 16 buffers initialized: 1280x0736, sizeimage 01413120, bytesperline 00001280
```

The height of 736 is what is stored in `fmt.fmt.pix.height` (or `fmt.fmt.pix_mp.height`), converted to byte size, and then passed to `v4l2_bufref_to_buf`, which will read several kilobytes over the input `AVFrame`'s data buffers. This caused a segmentation fault on Linux.

I encountered this bug in release 9.0.1, on NixOS with Linux kernel 7.2.8, on a Qualcomm Snapdragon X Elite system (Adreno X1-85 GPU). Patching FFmpeg with this change using the Nix build system solved the problem.


>From a27a4b44a4e3cfd4e7d0bcef1980a8e73c0c4498 Mon Sep 17 00:00:00 2001
From: trustytrojan <t@trustytrojan.dev>
Date: Sun, 27 Sep 2026 13:53:22 -0600
Subject: [PATCH] Prevent a buffer overread due to the Iris driver (a V4L2
 backend) sending back the size of its padded memory buffer.

This occurs when sending 1280x720 frames to the `h264_v4l2m2m` encoder. Running `ffmpeg -v debug -f lavfi -i testsrc=1280x720:d=1:rate=30 -pix_fmt nv12 -c:v h264_v4l2m2m -f null -` you will find this line in the debug output:

[h264_v4l2m2m @ 0xb243cd1f4d30] output: NV12 16 buffers initialized: 1280x0736, sizeimage 01413120, bytesperline 00001280

The value of 736 is what is stored in `fmt.fmt.pix.height` (or `fmt.fmt.pix_mp.height`), converted to byte size, and then passed to `v4l2_bufref_to_buf`, which will read several kilobytes over the input `AVFrame`'s data buffers.

The bug was first encountered in release 9.0.1, on NixOS with Linux kernel 7.2.8, on a Qualcomm Snapdragon X Elite system (Adreno X1-85 GPU). Patching ffmpeg with this change using the Nix build system solved the problem.
---
 libavcodec/v4l2_buffers.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
  

Patch

diff --git a/libavcodec/v4l2_buffers.c b/libavcodec/v4l2_buffers.c
index f96c26771b..0abe724a07 100644
--- a/libavcodec/v4l2_buffers.c
+++ b/libavcodec/v4l2_buffers.c
@@ -403,7 +403,7 @@  static int v4l2_buffer_swframe_to_buf(const AVFrame *frame, V4L2Buffer *out)
             planes_nb = FFMAX(planes_nb, desc->comp[i].plane + 1);
 
         for (i = 0; i < planes_nb; i++) {
-            int size, h = height;
+            int size, h = FFMIN(frame->height, height);
             if (i == 1 || i == 2) {
                 h = AV_CEIL_RSHIFT(h, desc->log2_chroma_h);
             }