From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:52593) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1RJ2at-0008Op-Kw for qemu-devel@nongnu.org; Wed, 26 Oct 2011 08:28:33 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1RJ2an-0008Cf-A7 for qemu-devel@nongnu.org; Wed, 26 Oct 2011 08:28:26 -0400 Received: from mx1.redhat.com ([209.132.183.28]:38331) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1RJ2am-0008CK-83 for qemu-devel@nongnu.org; Wed, 26 Oct 2011 08:28:24 -0400 Received: from int-mx10.intmail.prod.int.phx2.redhat.com (int-mx10.intmail.prod.int.phx2.redhat.com [10.5.11.23]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id p9QCSNRu022745 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Wed, 26 Oct 2011 08:28:23 -0400 From: Kevin Wolf Date: Wed, 26 Oct 2011 14:31:22 +0200 Message-Id: <1319632282-22725-8-git-send-email-kwolf@redhat.com> In-Reply-To: <1319632282-22725-1-git-send-email-kwolf@redhat.com> References: <1319632282-22725-1-git-send-email-kwolf@redhat.com> Subject: [Qemu-devel] [PATCH 7/7] vmdk: Fix possible segfaults List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: kwolf@redhat.com Data we read from the disk isn't necessarily null terminated and may not contain the string we're looking for. The code needs to be a bit more careful here. Signed-off-by: Kevin Wolf --- block/vmdk.c | 7 ++++++- 1 files changed, 6 insertions(+), 1 deletions(-) diff --git a/block/vmdk.c b/block/vmdk.c index fa0e8bd..8caaf0b 100644 --- a/block/vmdk.c +++ b/block/vmdk.c @@ -227,6 +227,7 @@ static uint32_t vmdk_read_cid(BlockDriverState *bs, int parent) cid_str_size = sizeof("CID"); } + desc[DESC_SIZE - 1] = '\0'; p_name = strstr(desc, cid_str); if (p_name != NULL) { p_name += cid_str_size; @@ -243,13 +244,17 @@ static int vmdk_write_cid(BlockDriverState *bs, uint32_t cid) BDRVVmdkState *s = bs->opaque; int ret; - memset(desc, 0, sizeof(desc)); ret = bdrv_pread(bs->file, s->desc_offset, desc, DESC_SIZE); if (ret < 0) { return ret; } + desc[DESC_SIZE - 1] = '\0'; tmp_str = strstr(desc, "parentCID"); + if (tmp_str == NULL) { + return -EINVAL; + } + pstrcpy(tmp_desc, sizeof(tmp_desc), tmp_str); p_name = strstr(desc, "CID"); if (p_name != NULL) { -- 1.7.6.4