From: Gerd Hoffmann <kraxel@redhat.com>
To: qemu-devel@nongnu.org
Cc: Gerd Hoffmann <kraxel@redhat.com>, qemu-stable@nongnu.org
Subject: [Qemu-devel] [PULL 5/5] ehci: make idt processing more robust
Date: Tue, 15 Dec 2015 11:02:33 +0100 [thread overview]
Message-ID: <1450173753-14562-6-git-send-email-kraxel@redhat.com> (raw)
In-Reply-To: <1450173753-14562-1-git-send-email-kraxel@redhat.com>
Make ehci_process_itd return an error in case we didn't do any actual
iso transfer because we've found no active transaction. That'll avoid
ehci happily run in circles forever if the guest builds a loop out of
idts.
This is CVE-2015-8558.
Cc: qemu-stable@nongnu.org
Reported-by: Qinghao Tang <luodalongde@gmail.com>
Tested-by: P J P <ppandit@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
---
hw/usb/hcd-ehci.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/hw/usb/hcd-ehci.c b/hw/usb/hcd-ehci.c
index 4e2161b..d07f228 100644
--- a/hw/usb/hcd-ehci.c
+++ b/hw/usb/hcd-ehci.c
@@ -1389,7 +1389,7 @@ static int ehci_process_itd(EHCIState *ehci,
{
USBDevice *dev;
USBEndpoint *ep;
- uint32_t i, len, pid, dir, devaddr, endp;
+ uint32_t i, len, pid, dir, devaddr, endp, xfers = 0;
uint32_t pg, off, ptr1, ptr2, max, mult;
ehci->periodic_sched_active = PERIODIC_ACTIVE;
@@ -1479,9 +1479,10 @@ static int ehci_process_itd(EHCIState *ehci,
ehci_raise_irq(ehci, USBSTS_INT);
}
itd->transact[i] &= ~ITD_XACT_ACTIVE;
+ xfers++;
}
}
- return 0;
+ return xfers ? 0 : -1;
}
--
1.8.3.1
next prev parent reply other threads:[~2015-12-15 10:02 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-12-15 10:02 [Qemu-devel] [PULL 0/5] usb: ehci idt fix, event support for mtp Gerd Hoffmann
2015-12-15 10:02 ` [Qemu-devel] [PULL 1/5] usb-mtp: use a list for keeping track of children Gerd Hoffmann
2015-12-15 10:02 ` [Qemu-devel] [PULL 2/5] usb-mtp: free objects on a mtp reset Gerd Hoffmann
2015-12-15 10:02 ` [Qemu-devel] [PULL 3/5] usb-mtp: Add support for inotify based file monitoring Gerd Hoffmann
2015-12-15 10:02 ` [Qemu-devel] [PULL 4/5] usb-mtp: add support for basic mtp events Gerd Hoffmann
2015-12-15 10:02 ` Gerd Hoffmann [this message]
2015-12-17 11:09 ` [Qemu-devel] [PULL 0/5] usb: ehci idt fix, event support for mtp Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1450173753-14562-6-git-send-email-kraxel@redhat.com \
--to=kraxel@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-stable@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).