qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [RFC V6 15/33] qcow2: Load and save deduplication table


From: Stefan Hajnoczi
Subject: Re: [Qemu-devel] [RFC V6 15/33] qcow2: Load and save deduplication table header extension.
Date: Thu, 7 Feb 2013 10:57:23 +0100
User-agent: Mutt/1.5.21 (2010-09-15)

On Wed, Feb 06, 2013 at 01:31:48PM +0100, Benoît Canet wrote:
> @@ -148,6 +158,19 @@ static int qcow2_read_extensions(BlockDriverState *bs, 
> uint64_t start_offset,
>              }
>              break;
>  
> +        case QCOW2_EXT_MAGIC_DEDUP_TABLE:
> +                ret = bdrv_pread(bs->file, offset,
> +                                 &dedup_table_extension, ext.len);

Buffer overflow if ext.len > sizeof(dedup_table_extension).  Please
check ext.len before using it.

> +                if (ret < 0) {
> +                    return ret;
> +                }
> +                s->dedup_table_offset =
> +                    be64_to_cpu(dedup_table_extension.offset);
> +                s->dedup_table_size =
> +                    be32_to_cpu(dedup_table_extension.size);
> +                s->dedup_hash_algo = dedup_table_extension.hash_algo;

Input validation for these fields (especially table size)?



reply via email to

[Prev in Thread] Current Thread [Next in Thread]