From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:41508) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TvXhu-0006vL-CU for qemu-devel@nongnu.org; Wed, 16 Jan 2013 13:27:29 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TvXht-0008J4-5L for qemu-devel@nongnu.org; Wed, 16 Jan 2013 13:27:26 -0500 Received: from mx1.redhat.com ([209.132.183.28]:29668) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TvXhs-0008Id-Sd for qemu-devel@nongnu.org; Wed, 16 Jan 2013 13:27:25 -0500 From: Eduardo Habkost Date: Wed, 16 Jan 2013 16:28:50 -0200 Message-Id: <1358360933-5323-6-git-send-email-ehabkost@redhat.com> In-Reply-To: <1358360933-5323-1-git-send-email-ehabkost@redhat.com> References: <1358360933-5323-1-git-send-email-ehabkost@redhat.com> Subject: [Qemu-devel] [PATCH 5/8] vl.c: numa_add(): Validate nodeid before using it List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org, Anthony Liguori Cc: Chegu Vinod Without this check, QEMU will corrupt memory if a too-large nodeid is provided in the command-line. e.g.: -numa node,mem=...,cpus=...,nodeid=65 This changes nodenr to unsigned long long, to avoid integer conversion issues when converting the strtoull() result to int. Signed-off-by: Eduardo Habkost --- Changes v2: - Implement change without creation of numa_node_add() function Changes v3: - Fix fprintf() format to use "%llu" for unsigned long long nodenr --- vl.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/vl.c b/vl.c index dabbba1..b39cd9a 100644 --- a/vl.c +++ b/vl.c @@ -1246,7 +1246,7 @@ static void numa_add(const char *optarg) char option[128]; char *endptr; unsigned long long value, endvalue; - int nodenr; + unsigned long long nodenr; value = endvalue = 0ULL; @@ -1267,6 +1267,11 @@ static void numa_add(const char *optarg) nodenr = strtoull(option, NULL, 10); } + if (nodenr >= MAX_NODES) { + fprintf(stderr, "qemu: invalid NUMA nodeid: %llu\n", nodenr); + exit(1); + } + if (get_param_value(option, 128, "mem", optarg) == 0) { node_mem[nodenr] = 0; } else { -- 1.7.11.7