From nobody Sat Sep 26 13:47:23 2026 Received: from cstnet.cn (smtp21.cstnet.cn [159.226.251.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2686040D578; Tue, 1 Sep 2026 02:23:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=159.226.251.21 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788229439; cv=none; b=OTCMtGhBOte8eBCAAd2fv1+4FKE+oSIxIvn/VhwquHzEhESLy4T3WeRVhlo30NVYqPikZW9xu4crlZ9u3zXmUjGVLrlNazIVZAnncSX3Ad/aYDnqSimVx03r76GhsKqtP6awvku4bNPT53GwZmKOm1rMwuqnc6r5kE1h7g7P84I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788229439; c=relaxed/simple; bh=oluzvyed/sHOVrhtCcGIOiW63Ie6M2mEovSeqwdyhqQ=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=puDTBIncDGDpFPvd9fxRR+uNM7ETJ9PuBwUFD3tLlHyzJ+/doVCgxlZSw/saV81Ij94XGnW1Fg7CjCI5mwfsV00GAqCvVoPSSI6GJsYxgX9MMuDlGeGLkGGAFs8wj0CaZ12ka7PrZ7/5++kBAmgIcvMTfLLPvGZRdCK6iDQDWyg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn; spf=pass smtp.mailfrom=iscas.ac.cn; arc=none smtp.client-ip=159.226.251.21 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iscas.ac.cn Received: from DESKTOP-L0HPE2S.localdomain (unknown [36.110.52.2]) by APP-01 (Coremail) with SMTP id qwCowABnO+8wN5ZqiVr6Bg--.26992S2; Tue, 01 Sep 2026 10:23:44 +0800 (CST) From: Haotian Zhang To: mchehab@kernel.org, nicolas@ndufresne.ca Cc: boris.brezillon@collabora.com, linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, Haotian Zhang Subject: [PATCH v3] media: v4l2-h264: Fix memcmp() size in B1 reference list comparison Date: Tue, 1 Sep 2026 10:23:09 +0800 Message-ID: <20260901022310.12184-1-vulab@iscas.ac.cn> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: qwCowABnO+8wN5ZqiVr6Bg--.26992S2 X-Coremail-Antispam: 1UD129KBjvJXoW7Ar1UKFW8JF47WF13Cry7GFg_yoW8WFW3p3 yrGrZxKrWUArZ5Zr48JayDGFn0yay8JFWI93ySk342q34qqFs3tw4vyFyUXF4Yk397u3yj 9rWqkrZ5tF43Zw7anT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUkE14x267AKxVWUJVW8JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26ryj6F1UM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26r4U JVWxJr1l84ACjcxK6I8E87Iv67AKxVW8Jr0_Cr1UM28EF7xvwVC2z280aVCY1x0267AKxV WxJr0_GcWle2I262IYc4CY6c8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2Wl Yx0E2Ix0cI8IcVAFwI0_JF0_Jw1lYx0Ex4A2jsIE14v26r4j6F4UMcvjeVCFs4IE7xkEbV WUJVW8JwACjcxG0xvY0x0EwIxGrwACjI8F5VA0II8E6IAqYI8I648v4I1lc7CjxVAaw2AF wI0_JF0_Jw1l42xK82IYc2Ij64vIr41l4I8I3I0E4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4 xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGVWUWwC2zVAF1VAY17CE14v26r126r1D MIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I 0E14v26r1j6r4UMIIF0xvE42xK8VAvwI8IcIk0rVWUJVWUCwCI42IY6I8E87Iv67AKxVWU JVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r1j6r4UYxBIdaVFxhVjvjDU0xZFpf9x0JUxcT PUUUUU= X-CM-SenderInfo: pyxotu46lvutnvoduhdfq/1tbiBwAQA2qVjVT3dwABsz Content-Type: text/plain; charset="utf-8" In v4l2_h264_build_b_ref_lists(), the B0/B1 list equality check passes the entry count builder->num_valid to memcmp() instead of a byte size. Since struct v4l2_h264_reference is two bytes (fields and index), only half of each list is compared, so distinct lists can be wrongly treated as equal and trigger an incorrect swap(b1_reflist[0], b1_reflist[1]). Change the memcmp() size argument to sizeof(b1_reflist[0]) * builder->num_valid so that the full byte length of both reference lists is compared. Fixes: 624922a2739b ("media: v4l2-core: Add helpers to build the H264 P/B0/= B1 reflists") Suggested-by: Nicolas Dufresne Signed-off-by: Haotian Zhang Reviewed-by: Nicolas Dufresne --- Changes in v2: - Use sizeof(b1_reflist[0]) * builder->num_valid for the memcmp() size to match the style of the memcpy() calls in the same function. Changes in v3: - Fix an extra closing parenthesis. --- drivers/media/v4l2-core/v4l2-h264.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/media/v4l2-core/v4l2-h264.c b/drivers/media/v4l2-core/= v4l2-h264.c index c00197d095e7..2323f559c6a3 100644 --- a/drivers/media/v4l2-core/v4l2-h264.c +++ b/drivers/media/v4l2-core/v4l2-h264.c @@ -440,7 +440,8 @@ v4l2_h264_build_b_ref_lists(const struct v4l2_h264_refl= ist_builder *builder, } =20 if (builder->num_valid > 1 && - !memcmp(b1_reflist, b0_reflist, builder->num_valid)) + !memcmp(b1_reflist, b0_reflist, + sizeof(b1_reflist[0]) * builder->num_valid)) swap(b1_reflist[0], b1_reflist[1]); =20 print_ref_list_b(builder, b0_reflist, 0); --=20 2.43.0