[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-devel] [PATCH] scsi: pvscsi: check command descriptor ring buf
From: |
Dmitry Fleytman |
Subject: |
Re: [Qemu-devel] [PATCH] scsi: pvscsi: check command descriptor ring buffer size |
Date: |
Mon, 23 May 2016 14:39:39 +0300 |
Reviewed-by: Dmitry Fleytman <address@hidden>
> On 23 May 2016, at 14:16 PM, Shmulik Ladkani <address@hidden> wrote:
>
> Hi,
>
> On Mon, 23 May 2016 16:18:05 +0530, address@hidden wrote:
>> From: Prasad J Pandit <address@hidden>
>>
>> Vmware Paravirtual SCSI emulation uses command descriptors to
>> process SCSI commands. These descriptors come with their ring
>> buffers. A guest could set the ring buffer size to an arbitrary
>> value leading to OOB access issue. Add check to avoid it.
>>
>> Reported-by: Li Qiang <address@hidden>
>> Signed-off-by: Prasad J Pandit <address@hidden>
>
> Reviewed-by: Shmulik Ladkani <address@hidden>