qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH v3 0/5] vmware-vga: fix CVE-2014-3689
@ 2014-10-28  9:50 Gerd Hoffmann
  2014-10-28  9:50 ` [Qemu-devel] [PATCH v3 1/5] vmware-vga: CVE-2014-3689: turn off hw accel Gerd Hoffmann
                   ` (5 more replies)
  0 siblings, 6 replies; 9+ messages in thread
From: Gerd Hoffmann @ 2014-10-28  9:50 UTC (permalink / raw)
  To: qemu-devel
  Cc: pmatouse, Intel.Product.Security.Incident.Response.Team, Don Koch,
	Gerd Hoffmann

  Hi,

vmware-vga emulation lacks sanity checks in the hardware acceleration
(blit + fill) functions.  This patch series plugs the holes.

v3 changes:
 * throw badcmd errors in case the rectangles fail the sanity checks.
v2 changes:
 * small whitespace fixup.
 * do fullscreen update on invalid update requests.

cheers,
  Gerd

Gerd Hoffmann (5):
  vmware-vga: CVE-2014-3689: turn off hw accel
  vmware-vga: add vmsvga_verify_rect
  vmware-vga: use vmsvga_verify_rect in vmsvga_update_rect
  vmware-vga: use vmsvga_verify_rect in vmsvga_copy_rect
  vmware-vga: use vmsvga_verify_rect in vmsvga_fill_rect

 hw/display/vmware_vga.c | 116 ++++++++++++++++++++++++++++++++----------------
 1 file changed, 78 insertions(+), 38 deletions(-)

-- 
1.8.3.1

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2014-10-28 18:09 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-10-28  9:50 [Qemu-devel] [PATCH v3 0/5] vmware-vga: fix CVE-2014-3689 Gerd Hoffmann
2014-10-28  9:50 ` [Qemu-devel] [PATCH v3 1/5] vmware-vga: CVE-2014-3689: turn off hw accel Gerd Hoffmann
2014-10-28  9:50 ` [Qemu-devel] [PATCH v3 2/5] vmware-vga: add vmsvga_verify_rect Gerd Hoffmann
2014-10-28  9:50 ` [Qemu-devel] [PATCH v3 3/5] vmware-vga: use vmsvga_verify_rect in vmsvga_update_rect Gerd Hoffmann
2014-10-28  9:50 ` [Qemu-devel] [PATCH v3 4/5] vmware-vga: use vmsvga_verify_rect in vmsvga_copy_rect Gerd Hoffmann
2014-10-28 18:04   ` Don Koch
2014-10-28  9:50 ` [Qemu-devel] [PATCH v3 5/5] vmware-vga: use vmsvga_verify_rect in vmsvga_fill_rect Gerd Hoffmann
2014-10-28 18:05   ` Don Koch
2014-10-28 18:09 ` [Qemu-devel] [PATCH v3 0/5] vmware-vga: fix CVE-2014-3689 Don Koch

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).