From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:60922) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rkqzs-0003bY-JB for qemu-devel@nongnu.org; Wed, 11 Jan 2012 00:45:17 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Rkqzl-0000Ab-6W for qemu-devel@nongnu.org; Wed, 11 Jan 2012 00:45:16 -0500 Received: from ozlabs.org ([203.10.76.45]:56700) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rkqzk-00005M-ND for qemu-devel@nongnu.org; Wed, 11 Jan 2012 00:45:09 -0500 From: David Gibson Date: Wed, 11 Jan 2012 16:44:49 +1100 Message-Id: <1326260692-7272-2-git-send-email-david@gibson.dropbear.id.au> In-Reply-To: <1326260692-7272-1-git-send-email-david@gibson.dropbear.id.au> References: <1326260692-7272-1-git-send-email-david@gibson.dropbear.id.au> Subject: [Qemu-devel] [PATCH 1/4] load_image_targphys() should enforce the max size List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: anthony@codemonkey.ws Cc: agraf@suse.de, qemu-devel@nongnu.org From: Benjamin Herrenschmidt load_image_targphys() gets passed a max size for the file, but doesn't enforce it at all. Add a check and return -1 (error) if the file is too big, without loading it. Signed-off-by: Benjamin Herrenschmidt Signed-off-by: David Gibson --- hw/loader.c | 2 ++ 1 files changed, 2 insertions(+), 0 deletions(-) diff --git a/hw/loader.c b/hw/loader.c index 446b628..7ad9e22 100644 --- a/hw/loader.c +++ b/hw/loader.c @@ -108,6 +108,8 @@ int load_image_targphys(const char *filename, int size; size = get_image_size(filename); + if (size > max_sz) + return -1; if (size > 0) rom_add_file_fixed(filename, addr, -1); return size; -- 1.7.7.3