qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Juan Quintela <quintela@redhat.com>
To: qemu-devel@nongnu.org
Cc: "Michael S. Tsirkin" <mst@redhat.com>
Subject: [Qemu-devel] [PATCH 07/36] ahci: fix buffer overrun on invalid state load
Date: Mon,  5 May 2014 22:30:05 +0200	[thread overview]
Message-ID: <1399321834-31310-8-git-send-email-quintela@redhat.com> (raw)
In-Reply-To: <1399321834-31310-1-git-send-email-quintela@redhat.com>

From: "Michael S. Tsirkin" <mst@redhat.com>

CVE-2013-4526

Within hw/ide/ahci.c, VARRAY refers to ports which is also loaded.  So
we use the old version of ports to read the array but then allow any
value for ports.  This can cause the code to overflow.

There's no reason to migrate ports - it never changes.
So just make sure it matches.

Reported-by: Anthony Liguori <anthony@codemonkey.ws>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Juan Quintela <quintela@redhat.com>
---
 hw/ide/ahci.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/ide/ahci.c b/hw/ide/ahci.c
index 50327ff..e57c583 100644
--- a/hw/ide/ahci.c
+++ b/hw/ide/ahci.c
@@ -1293,7 +1293,7 @@ const VMStateDescription vmstate_ahci = {
         VMSTATE_UINT32(control_regs.impl, AHCIState),
         VMSTATE_UINT32(control_regs.version, AHCIState),
         VMSTATE_UINT32(idp_index, AHCIState),
-        VMSTATE_INT32(ports, AHCIState),
+        VMSTATE_INT32_EQUAL(ports, AHCIState),
         VMSTATE_END_OF_LIST()
     },
 };
-- 
1.9.0

  parent reply	other threads:[~2014-05-05 20:31 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-05-05 20:29 [Qemu-devel] [PULL 00/36] migration queue Juan Quintela
2014-05-05 20:29 ` [Qemu-devel] [PATCH 01/36] vmstate: reduce code duplication Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 02/36] vmstate: add VMS_MUST_EXIST Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 03/36] vmstate: add VMSTATE_VALIDATE Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 04/36] virtio-net: fix buffer overflow on invalid state load Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 05/36] virtio-net: out-of-bounds buffer write " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 06/36] virtio: " Juan Quintela
2014-05-05 20:30 ` Juan Quintela [this message]
2014-05-05 20:30 ` [Qemu-devel] [PATCH 08/36] hpet: fix buffer overrun " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 09/36] hw/pci/pcie_aer.c: fix buffer overruns " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 10/36] pl022: fix buffer overun " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 11/36] vmstate: fix buffer overflow in target-arm/machine.c Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 12/36] virtio: avoid buffer overrun on incoming migration Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 13/36] virtio: validate num_sg when mapping Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 14/36] pxa2xx: avoid buffer overrun on incoming migration Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 15/36] ssd0323: fix buffer overun on invalid state load Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 16/36] tsc210x: fix buffer overrun " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 17/36] zaurus: " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 18/36] virtio-scsi: " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 19/36] vmstate: s/VMSTATE_INT32_LE/VMSTATE_INT32_POSITIVE_LE/ Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 20/36] usb: sanity check setup_index+setup_len in post_load Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 21/36] savevm: Ignore minimum_version_id_old if there is no load_state_old Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 22/36] ssi-sd: fix buffer overrun on invalid state load Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 23/36] openpic: avoid buffer overrun on incoming migration Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 24/36] virtio-net: out-of-bounds buffer write on load Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 25/36] virtio: validate config_len " Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 26/36] Disallow outward migration while awaiting incoming migration Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 27/36] Make qemu_peek_buffer loop until it gets it's data Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 28/36] Count used RAMBlock pages for migration_dirty_pages Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 29/36] Provide init function for ram migration Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 30/36] Init the XBZRLE.lock in ram_mig_init Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 31/36] Coverity: Fix failure path for qemu_accept in migration Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 32/36] migration: remove duplicate code Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 33/36] XBZRLE: Fix one XBZRLE corruption issues Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 34/36] migration: Add counts of updating the dirty bitmap Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 35/36] migration: expose the bitmap_sync_count to the end Juan Quintela
2014-05-05 20:30 ` [Qemu-devel] [PATCH 36/36] migration: expose xbzrle cache miss rate Juan Quintela
2014-05-07 15:09 ` [Qemu-devel] [PULL 00/36] migration queue Peter Maydell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1399321834-31310-8-git-send-email-quintela@redhat.com \
    --to=quintela@redhat.com \
    --cc=mst@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).