[FFmpeg-devel,PR] Prevent a buffer overread due to the Iris driver (a V4L2 backend) sending back the size of its padded memory buffer (PR #24742)
| Message ID | 20260927195650.AC6E72FF9E@ffbox0-bg.ffmpeg.org |
|---|---|
| State | New |
| Headers |
Return-Path: <ffmpeg-devel-bounces@ffmpeg.org> Delivered-To: patchwork@ffbox0-bg.ffmpeg.org Received: from ffbox0-bg.ffmpeg.org by ffbox0-bg.ffmpeg.org with LMTP id aDp5BBZ1uWpGRDcA028elg (envelope-from <ffmpeg-devel-bounces@ffmpeg.org>) for <patchwork@ffbox0-bg.ffmpeg.org>; Sun, 27 Sep 2026 22:57:10 +0300 Received: from [172.18.0.3] (unknown [172.18.0.3]) by ffbox0-bg.ffmpeg.org (Postfix) with ESMTP id F0CBE37AFB; Sun, 27 Sep 2026 22:57:09 +0300 (EEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ffmpeg.org; s=mail; t=1790539029; h=from:from:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding:list-id:list-help: list-owner:list-unsubscribe:list-subscribe:list-post; bh=7lHbW/xyqUnDPy4CcXkellUMeP7izhVZCETpS8+kSCQ=; b=DWOJR+T+FMZz8jhgtrnXu2xiEm2DUUrwTqLP7j7BVWtp8cmzjDq8zUyuiYKYDyyjriDpJt g8XHQAtcnY1phVoMA0hBjQhgF26ro7A3nteXvqiiAw/++w277lgPzWCEs1MIO2q8kSay0Z ck2hTwtfOZyio8K3OdLC7GVpAJ0FFyZcTqrlGKqQfUpmAKuUjE4bltfpKgeTLadmK4jHQf VFTvhaFfnxs0xZHKBGEljXCk0rLuvN7wbaHtGEHRWE2MN4lAF6fsQMQ/ixR36AxK7Cr9bp PC/HAidw9E/ZxExRVbsSy6jjU7NXcXHvVys2+a6gTBZEOTPvp12rs6hkxGdEPg== ARC-Seal: i=1; cv=none; a=rsa-sha256; d=ffmpeg.org; s=arc; t=1790539016; b=lpl3VGqksnzWv02E0wq9ML9zS6yJGE9enamBd+t+KvFZrhxEhP7ZvTqtlxG8lLpcztsz5 3ZtElVXjWJ+n8HpRQaJ+EMn87btaVUBJFwTD+y3tdSLRPmRWuxdtigXvDurMtJ/nDsMk5RD YXYgKP57d64OVc06k3uURuyCALSgitmj/9JDaFL+QbJgF0rp6Lbme2ybH3ZcPmjrb/q6Dqr lV7dIiVTMCeIUgZOvPWLPRyFPwp1RIh0d9MA6pHXVf3WuIWzzUsIrnagwDp3wOQ6YKdmF+/ BUy3QUC2Hx/jlpn6PUqWPwHGhSkEJdT6etkX0BvPgaF4DPw/Z2wLYTKKVOgA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=ffmpeg.org; s=arc; t=1790539016; h=from : sender : reply-to : subject : date : message-id : to : cc : mime-version : content-type : content-transfer-encoding : content-id : content-description : resent-date : resent-from : resent-sender : resent-to : resent-cc : resent-message-id : in-reply-to : references : list-id : list-help : list-unsubscribe : list-subscribe : list-post : list-owner : list-archive; bh=Jv0YC17tWjV/pWxt/tBAJMlBFAgre2wEPnAM3afBIW8=; b=uL17GZyAOhPc1EoHe5vrBzU/CAlMEkusCOlkL6U1EpLlPNzYcSGoX7/ztLb//H+CMhTKy ytuKmujwlYXCObYaavrVA7uOFXejOQ0CM8Hk8uEeCamZnuV89NJ67MNPzjC/lgXY0lGV+dR AzF+w3trWzc9qxw0I8vR4InIfCErr/wcINvTspWyLzIEcCFa1JbcqO8HWT8weNtpozA4J/V /WW6/Q4Q2Jht69rhU0wMfcTpkUB79mLajxuGYicQ4HhHusKCph6z6KVVAewCnN9U6aU6DRB k5cZNyA0ykeF8ZqvzViyM5Ecqk3hFBevNbD+3LwLzygY9QAN79Myop50ocdQ== ARC-Authentication-Results: i=1; ffmpeg.org; dkim=pass header.d=ffmpeg.org; arc=none; dmarc=pass header.from=ffmpeg.org policy.dmarc=quarantine Authentication-Results: ffmpeg.org; dkim=pass header.d=ffmpeg.org; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=ffmpeg.org policy.dmarc=quarantine DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ffmpeg.org; s=mail; t=1790539010; h=from:from:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=rILrpv3emB4XMw0eJpBS2K0586C7Nn/G798ZALxB34s=; b=LvOKuEv4jT1eNQbovml9xERETHkDckue1bZwWTt6oU9ABqy3aNn/iJA+FsrWFMpSmQMwBH 0OH5AkSeat9olQE2dSYGNKDk0WWBbH8S9Rr/TLHpVnBI/zNEvydZFdmqO9bFu6AkPmA2AO U2TM23trjt7iM7tZIk5HL+dXqRbupvQBS+tVYna2mOk82us0dj4vXsSRDMW60lFOl80XXB HaXU63O+U04gvUkmwStIdwhlmWIyDJn//4aVDNgiUz6K4NexGZ+6KGPJEzVRF3OPEHNmKT Ue/i/gaOjRirVsVK/xD6UwomoFAR6TbmX+aFbHSNGxbE5iyr4plAtuT/X4pC3Q== MIME-Version: 1.0 To: ffmpeg-devel@ffmpeg.org Date: Sun, 27 Sep 2026 19:56:50 -0000 Message-Id: <20260927195650.AC6E72FF9E@ffbox0-bg.ffmpeg.org> Message-ID-Hash: EMZ5AFPHWWY7E222GG26LCQRZPV75NWS X-Message-ID-Hash: EMZ5AFPHWWY7E222GG26LCQRZPV75NWS X-MailFrom: code@ffmpeg.org X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-ffmpeg-devel.ffmpeg.org-0; header-match-ffmpeg-devel.ffmpeg.org-1; header-match-ffmpeg-devel.ffmpeg.org-2; header-match-ffmpeg-devel.ffmpeg.org-3; emergency; member-moderation X-Mailman-Version: 3.3.10 Precedence: list Reply-To: FFmpeg development discussions and patches <ffmpeg-devel@ffmpeg.org> Subject: [FFmpeg-devel] [PR] Prevent a buffer overread due to the Iris driver (a V4L2 backend) sending back the size of its padded memory buffer (PR #24742) List-Id: FFmpeg development discussions and patches <ffmpeg-devel.ffmpeg.org> Archived-At: <https://lists.ffmpeg.org/archives/list/ffmpeg-devel@ffmpeg.org/message/EMZ5AFPHWWY7E222GG26LCQRZPV75NWS/> Archived-At: <https://lists.ffmpeg.org/lore/ffmpeg-devel/20260927195650.AC6E72FF9E@ffbox0-bg.ffmpeg.org/> List-Archive: <https://lists.ffmpeg.org/archives/list/ffmpeg-devel@ffmpeg.org/> List-Archive: <https://lists.ffmpeg.org/lore/ffmpeg-devel/> List-Help: <mailto:ffmpeg-devel-request@ffmpeg.org?subject=help> List-Owner: <mailto:ffmpeg-devel-owner@ffmpeg.org> List-Post: <mailto:ffmpeg-devel@ffmpeg.org> List-Subscribe: <mailto:ffmpeg-devel-join@ffmpeg.org> List-Unsubscribe: <mailto:ffmpeg-devel-leave@ffmpeg.org> From: trustytrojan via ffmpeg-devel <ffmpeg-devel@ffmpeg.org> Cc: trustytrojan <code@ffmpeg.org> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-getmail-retrieved-from-mailbox: INBOX |
| Series |
[FFmpeg-devel,PR] Prevent a buffer overread due to the Iris driver (a V4L2 backend) sending back the size of its padded memory buffer (PR #24742)
|
|
Commit Message
t-boiko
Sept. 27, 2026, 7:56 p.m. UTC
PR #24742 opened by trustytrojan URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24742 Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24742.patch This occurs when sending 1280x720 frames to the `h264_v4l2m2m` encoder. When running the following command: ``` ffmpeg -v debug -f lavfi -i testsrc=1280x720:d=1:rate=30 -pix_fmt nv12 -c:v h264_v4l2m2m -f null - ``` you will find this line in the debug output: ``` [h264_v4l2m2m @ 0xb243cd1f4d30] output: NV12 16 buffers initialized: 1280x0736, sizeimage 01413120, bytesperline 00001280 ``` The height of 736 is what is stored in `fmt.fmt.pix.height` (or `fmt.fmt.pix_mp.height`), converted to byte size, and then passed to `v4l2_bufref_to_buf`, which will read several kilobytes over the input `AVFrame`'s data buffers. This caused a segmentation fault on Linux. I encountered this bug in release 9.0.1, on NixOS with Linux kernel 7.2.8, on a Qualcomm Snapdragon X Elite system (Adreno X1-85 GPU). Patching FFmpeg with this change using the Nix build system solved the problem. >From a27a4b44a4e3cfd4e7d0bcef1980a8e73c0c4498 Mon Sep 17 00:00:00 2001 From: trustytrojan <t@trustytrojan.dev> Date: Sun, 27 Sep 2026 13:53:22 -0600 Subject: [PATCH] Prevent a buffer overread due to the Iris driver (a V4L2 backend) sending back the size of its padded memory buffer. This occurs when sending 1280x720 frames to the `h264_v4l2m2m` encoder. Running `ffmpeg -v debug -f lavfi -i testsrc=1280x720:d=1:rate=30 -pix_fmt nv12 -c:v h264_v4l2m2m -f null -` you will find this line in the debug output: [h264_v4l2m2m @ 0xb243cd1f4d30] output: NV12 16 buffers initialized: 1280x0736, sizeimage 01413120, bytesperline 00001280 The value of 736 is what is stored in `fmt.fmt.pix.height` (or `fmt.fmt.pix_mp.height`), converted to byte size, and then passed to `v4l2_bufref_to_buf`, which will read several kilobytes over the input `AVFrame`'s data buffers. The bug was first encountered in release 9.0.1, on NixOS with Linux kernel 7.2.8, on a Qualcomm Snapdragon X Elite system (Adreno X1-85 GPU). Patching ffmpeg with this change using the Nix build system solved the problem. --- libavcodec/v4l2_buffers.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/libavcodec/v4l2_buffers.c b/libavcodec/v4l2_buffers.c index f96c26771b..0abe724a07 100644 --- a/libavcodec/v4l2_buffers.c +++ b/libavcodec/v4l2_buffers.c @@ -403,7 +403,7 @@ static int v4l2_buffer_swframe_to_buf(const AVFrame *frame, V4L2Buffer *out) planes_nb = FFMAX(planes_nb, desc->comp[i].plane + 1); for (i = 0; i < planes_nb; i++) { - int size, h = height; + int size, h = FFMIN(frame->height, height); if (i == 1 || i == 2) { h = AV_CEIL_RSHIFT(h, desc->log2_chroma_h); }