qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH] pcihp: fix possible array out of bounds
@ 2014-08-19  7:18 arei.gonglei
  2014-08-19 14:59 ` Marcel Apfelbaum
  2014-08-19 15:12 ` Peter Crosthwaite
  0 siblings, 2 replies; 5+ messages in thread
From: arei.gonglei @ 2014-08-19  7:18 UTC (permalink / raw)
  To: qemu-devel; +Cc: Gonglei, weidong.huang, mst

From: Gonglei <arei.gonglei@huawei.com>

When 'bsel == ACPI_PCIHP_MAX_HOTPLUG_BUS', the
s->acpi_pcihp_pci_status[bsel] array will out of bounds.

Add check for this.

Signed-off-by: Gonglei <arei.gonglei@huawei.com>
---
 hw/acpi/pcihp.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/acpi/pcihp.c b/hw/acpi/pcihp.c
index fae663a..34dedf1 100644
--- a/hw/acpi/pcihp.c
+++ b/hw/acpi/pcihp.c
@@ -231,7 +231,7 @@ static uint64_t pci_read(void *opaque, hwaddr addr, unsigned int size)
     uint32_t val = 0;
     int bsel = s->hotplug_select;
 
-    if (bsel < 0 || bsel > ACPI_PCIHP_MAX_HOTPLUG_BUS) {
+    if (bsel < 0 || bsel >= ACPI_PCIHP_MAX_HOTPLUG_BUS) {
         return 0;
     }
 
-- 
1.7.12.4

^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2014-08-20  2:25 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-08-19  7:18 [Qemu-devel] [PATCH] pcihp: fix possible array out of bounds arei.gonglei
2014-08-19 14:59 ` Marcel Apfelbaum
2014-08-20  2:22   ` Gonglei (Arei)
2014-08-19 15:12 ` Peter Crosthwaite
2014-08-20  2:24   ` Gonglei (Arei)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).