qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [PATCH v4 08/30] ahci: fix buffer overrun on invalid st


From: Peter Maydell
Subject: Re: [Qemu-devel] [PATCH v4 08/30] ahci: fix buffer overrun on invalid state load
Date: Mon, 31 Mar 2014 16:31:57 +0100

On 31 March 2014 15:16, Michael S. Tsirkin <address@hidden> wrote:
> CVE-2013-4526
>
> Within hw/ide/ahci.c, VARRAY refers to ports which is also loaded.  So
> we use the old version of ports to read the array but then allow any
> value for ports.  This can cause the code to overflow.
>
> There's no reason to migrate ports - it never changes.
> So just make sure it matches.
>
> Reported-by: Anthony Liguori <address@hidden>
> Signed-off-by: Michael S. Tsirkin <address@hidden>
> ---

Reviewed-by: Peter Maydell <address@hidden>

-- PMM



reply via email to

[Prev in Thread] Current Thread [Next in Thread]