diff options
author | Michael S. Tsirkin <mst@redhat.com> | 2014-04-03 19:51:31 +0300 |
---|---|---|
committer | Juan Quintela <quintela@redhat.com> | 2014-05-05 22:15:02 +0200 |
commit | 5f691ff91d323b6f97c6600405a7f9dc115a0ad1 (patch) | |
tree | b74c3b71e045d1fda8480300959fcb6689400f92 /hw/pci/pcie_port.c | |
parent | 3f1c49e2136fa08ab1ef3183fd55def308829584 (diff) | |
download | hqemu-5f691ff91d323b6f97c6600405a7f9dc115a0ad1.zip hqemu-5f691ff91d323b6f97c6600405a7f9dc115a0ad1.tar.gz |
hw/pci/pcie_aer.c: fix buffer overruns on invalid state load
4) CVE-2013-4529
hw/pci/pcie_aer.c pcie aer log can overrun the buffer if log_num is
too large
There are two issues in this file:
1. log_max from remote can be larger than on local
then buffer will overrun with data coming from state file.
2. log_num can be larger then we get data corruption
again with an overflow but not adversary controlled.
Fix both issues.
Reported-by: Anthony Liguori <anthony@codemonkey.ws>
Reported-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Reviewed-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Signed-off-by: Juan Quintela <quintela@redhat.com>
Diffstat (limited to 'hw/pci/pcie_port.c')
0 files changed, 0 insertions, 0 deletions