qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Qemu-devel] [Bug 1355697] [NEW] qemu-img: Segfault on a fuzzed image wi


From: Maria Kustova
Subject: [Qemu-devel] [Bug 1355697] [NEW] qemu-img: Segfault on a fuzzed image with large values of L1/L2 entries
Date: Tue, 12 Aug 2014 09:47:05 -0000

Public bug reported:

'qemu-img check -r all/leaks' failed with a segmentation fault on the
fuzzed image with L1/L2 entry values having UINT64 border values.

Sequence:
 1. Unpack the attached archive, make a copy of test.img
 2. Put copy.img and backing_img.raw in the same directory
 3. Execute
   
qemu-img check -f qcow2 -r all copy.img

Result: qemu-img was killed by SIGSEGV.

The qemu-img execution log can be found in the attached archive.


qemu.git HEAD 2d591ce2aeebf

** Affects: qemu
     Importance: Undecided
         Status: New

** Attachment added: "images.n.traces.tar.gz"
   
https://bugs.launchpad.net/bugs/1355697/+attachment/4175257/+files/images.n.traces.tar.gz

-- 
You received this bug notification because you are a member of qemu-
devel-ml, which is subscribed to QEMU.
https://bugs.launchpad.net/bugs/1355697

Title:
  qemu-img: Segfault on a fuzzed image with large values of L1/L2
  entries

Status in QEMU:
  New

Bug description:
  'qemu-img check -r all/leaks' failed with a segmentation fault on the
  fuzzed image with L1/L2 entry values having UINT64 border values.

  Sequence:
   1. Unpack the attached archive, make a copy of test.img
   2. Put copy.img and backing_img.raw in the same directory
   3. Execute
     
  qemu-img check -f qcow2 -r all copy.img

  Result: qemu-img was killed by SIGSEGV.

  The qemu-img execution log can be found in the attached archive.

  
  qemu.git HEAD 2d591ce2aeebf

To manage notifications about this bug go to:
https://bugs.launchpad.net/qemu/+bug/1355697/+subscriptions



reply via email to

[Prev in Thread] Current Thread [Next in Thread]