|
From: | Paolo Bonzini |
Subject: | Re: [Qemu-devel] [PULL 23/36] cadence_gem: Add queue support |
Date: | Mon, 26 Sep 2016 13:01:52 +0200 |
User-agent: | Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.3.0 |
On 22/09/2016 19:22, Peter Maydell wrote: > + case GEM_RECEIVE_Q1_PTR ... GEM_RECEIVE_Q15_PTR: > + s->rx_desc_addr[offset - GEM_RECEIVE_Q1_PTR + 1] = val; > + break; MAX_PRIORITY_QUEUES is still 8, so this can cause an out-of-bounds write in s->rx_desc_addr (and likewise for s->tx_addr). Paolo
[Prev in Thread] | Current Thread | [Next in Thread] |