[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH v3] hw/net/virtio-net.c: fix crash in iov_copy()
From: |
Michael S. Tsirkin |
Subject: |
Re: [PATCH v3] hw/net/virtio-net.c: fix crash in iov_copy() |
Date: |
Mon, 1 Jul 2024 16:14:25 -0400 |
On Thu, Jun 13, 2024 at 05:35:30PM +0300, Dmitry Frolov wrote:
> A crash found while fuzzing device virtio-net-socket-check-used.
> Assertion "offset == 0" in iov_copy() fails if less than guest_hdr_len bytes
> were transmited.
>
> Signed-off-by: Dmitry Frolov <frolov@swemel.ru>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Jason, are you merging this?
> ---
> v1: https://patchew.org/QEMU/20240527133140.218300-2-frolov@swemel.ru/
> v2: broken
> v3: goto instead of repeating code
> ---
> hw/net/virtio-net.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/hw/net/virtio-net.c b/hw/net/virtio-net.c
> index 9c7e85caea..8f30972708 100644
> --- a/hw/net/virtio-net.c
> +++ b/hw/net/virtio-net.c
> @@ -2735,6 +2735,10 @@ static int32_t virtio_net_flush_tx(VirtIONetQueue *q)
> */
> assert(n->host_hdr_len <= n->guest_hdr_len);
> if (n->host_hdr_len != n->guest_hdr_len) {
> + if (iov_size(out_sg, out_num) < n->guest_hdr_len) {
> + virtio_error(vdev, "virtio-net header is invalid");
> + goto detach;
> + }
> unsigned sg_num = iov_copy(sg, ARRAY_SIZE(sg),
> out_sg, out_num,
> 0, n->host_hdr_len);
> --
> 2.43.0
[Prev in Thread] |
Current Thread |
[Next in Thread] |
- Re: [PATCH v3] hw/net/virtio-net.c: fix crash in iov_copy(),
Michael S. Tsirkin <=