From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1Kqitg-0003B0-De for qemu-devel@nongnu.org; Fri, 17 Oct 2008 02:33:16 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1Kqite-0003Ad-Mg for qemu-devel@nongnu.org; Fri, 17 Oct 2008 02:33:15 -0400 Received: from [199.232.76.173] (port=48857 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1Kqite-0003Aa-Hm for qemu-devel@nongnu.org; Fri, 17 Oct 2008 02:33:14 -0400 Received: from mx20.gnu.org ([199.232.41.8]:16342) by monty-python.gnu.org with esmtps (TLS-1.0:RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1Kqitd-0000C6-Pd for qemu-devel@nongnu.org; Fri, 17 Oct 2008 02:33:14 -0400 Received: from nf-out-0910.google.com ([64.233.182.186]) by mx20.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1KqitW-0006U2-SN for qemu-devel@nongnu.org; Fri, 17 Oct 2008 02:33:07 -0400 Received: by nf-out-0910.google.com with SMTP id b2so253964nfb.12 for ; Thu, 16 Oct 2008 23:33:04 -0700 (PDT) From: "Kirill A. Shutemov" Date: Fri, 17 Oct 2008 09:34:23 +0300 Message-Id: <1224225264-8483-1-git-send-email-kirill@shutemov.name> In-Reply-To: <1223892640-15545-13-git-send-email-kirill@shutemov.name> References: <1223892640-15545-13-git-send-email-kirill@shutemov.name> Subject: [Qemu-devel] [PATCH] mmap: add check if requested memory area fits target address space Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: "Kirill A. Shutemov" Signed-off-by: Kirill A. Shutemov --- linux-user/mmap.c | 5 +++++ 1 files changed, 5 insertions(+), 0 deletions(-) diff --git a/linux-user/mmap.c b/linux-user/mmap.c index bc20f4b..9a2f355 100644 --- a/linux-user/mmap.c +++ b/linux-user/mmap.c @@ -388,6 +388,11 @@ abi_long target_mmap(abi_ulong start, abi_ulong len, int prot, end = start + len; real_end = HOST_PAGE_ALIGN(end); + if ((unsigned long)start + len > (abi_ulong) -1) { + errno = EINVAL; + goto fail; + } + for(addr = real_start; addr < real_end; addr += TARGET_PAGE_SIZE) { flg = page_get_flags(addr); if (flg & PAGE_RESERVED) { -- 1.5.6.5.GIT