From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:57041) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SpDSf-0000A9-8C for qemu-devel@nongnu.org; Thu, 12 Jul 2012 03:05:23 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1SpDSe-0007Wa-Cm for qemu-devel@nongnu.org; Thu, 12 Jul 2012 03:05:17 -0400 Received: from mail-pb0-f45.google.com ([209.85.160.45]:46795) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1SpDSe-0007WW-6Z for qemu-devel@nongnu.org; Thu, 12 Jul 2012 03:05:16 -0400 Received: by pbbro12 with SMTP id ro12so3458673pbb.4 for ; Thu, 12 Jul 2012 00:05:15 -0700 (PDT) From: Ronnie Sahlberg Date: Thu, 12 Jul 2012 17:05:11 +1000 Message-Id: <1342076712-27013-1-git-send-email-ronniesahlberg@gmail.com> Subject: [Qemu-devel] [PATCH] SCSI improved LBA-out-of-range checks BUGFIX List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: pbonzini@redhat.com, qemu-devel@nongnu.org Paolo, Sorry but the previous patch was bad. Use this patch instead it uses the correct check of if (r->req.cmd.lba > r->req.cmd.lba + len || r->req.cmd.lba + len > s->qdev.max_lba + 1) {