qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Qemu-devel] [PATCH 8/8] hw/i386: fix unbounded stack for load_multiboot


From: Peter Xu
Subject: [Qemu-devel] [PATCH 8/8] hw/i386: fix unbounded stack for load_multiboot
Date: Tue, 8 Mar 2016 15:00:46 +0800

Suggested-by: Paolo Bonzini <address@hidden>
CC: Paolo Bonzini <address@hidden>
CC: Richard Henderson <address@hidden>
CC: Eduardo Habkost <address@hidden>
CC: "Michael S. Tsirkin" <address@hidden>
Signed-off-by: Peter Xu <address@hidden>
---
 hw/i386/multiboot.c | 10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

diff --git a/hw/i386/multiboot.c b/hw/i386/multiboot.c
index 9e164e6..0eecb9a 100644
--- a/hw/i386/multiboot.c
+++ b/hw/i386/multiboot.c
@@ -159,6 +159,12 @@ int load_multiboot(FWCfgState *fw_cfg,
     uint8_t *mb_bootinfo_data;
     uint32_t cmdline_len;
 
+#define __KERN_FNAME_LEN (1024)
+#define __KERN_CMDLINE_LEN (4096)
+
+    assert(strlen(kernel_filename) + 1 >= __KERN_FNAME_LEN);
+    assert(strlen(kernel_cmdline) + 1 >= __KERN_CMDLINE_LEN);
+
     /* Ok, let's see if it is a multiboot image.
        The header is 12x32bit long, so the latest entry may be 8192 - 48. */
     for (i = 0; i < (8192 - 48); i += 4) {
@@ -324,7 +330,7 @@ int load_multiboot(FWCfgState *fw_cfg,
     }
 
     /* Commandline support */
-    char kcmdline[strlen(kernel_filename) + strlen(kernel_cmdline) + 2];
+    char kcmdline[__KERN_FNAME_LEN + __KERN_CMDLINE_LEN];
     snprintf(kcmdline, sizeof(kcmdline), "%s %s",
              kernel_filename, kernel_cmdline);
     stl_p(bootinfo + MBI_CMDLINE, mb_add_cmdline(&mbs, kcmdline));
@@ -370,4 +376,6 @@ int load_multiboot(FWCfgState *fw_cfg,
     nb_option_roms++;
 
     return 1; /* yes, we are multiboot */
+#undef __KERN_FNAME_LEN
+#undef __KERN_CMDLINE_LEN
 }
-- 
2.4.3




reply via email to

[Prev in Thread] Current Thread [Next in Thread]