diff options
author | Michael S. Tsirkin <mst@redhat.com> | 2014-04-03 19:51:35 +0300 |
---|---|---|
committer | Juan Quintela <quintela@redhat.com> | 2014-05-05 22:15:02 +0200 |
commit | d8d0a0bc7e194300e53a346d25fe5724fd588387 (patch) | |
tree | bd483570cd987b5157c25fde9c93dc34f76fd9a6 /tests/virtio-balloon-test.c | |
parent | 5f691ff91d323b6f97c6600405a7f9dc115a0ad1 (diff) | |
download | hqemu-d8d0a0bc7e194300e53a346d25fe5724fd588387.zip hqemu-d8d0a0bc7e194300e53a346d25fe5724fd588387.tar.gz |
pl022: fix buffer overun on invalid state load
CVE-2013-4530
pl022.c did not bounds check tx_fifo_head and
rx_fifo_head after loading them from file and
before they are used to dereference array.
Reported-by: Michael S. Tsirkin <mst@redhat.com
Reported-by: Anthony Liguori <anthony@codemonkey.ws>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Juan Quintela <quintela@redhat.com>
Diffstat (limited to 'tests/virtio-balloon-test.c')
0 files changed, 0 insertions, 0 deletions