From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:58873) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TlI2x-0000Nd-Eu for qemu-devel@nongnu.org; Wed, 19 Dec 2012 06:42:50 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TlI2v-0007ow-1f for qemu-devel@nongnu.org; Wed, 19 Dec 2012 06:42:47 -0500 Received: from mx1.redhat.com ([209.132.183.28]:47376) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TlI2u-0007or-PB for qemu-devel@nongnu.org; Wed, 19 Dec 2012 06:42:44 -0500 Date: Wed, 19 Dec 2012 12:42:34 +0100 From: Stefan Hajnoczi Message-ID: <20121219114234.GC5832@stefanha-thinkpad.redhat.com> References: <20121205121317.GC6887@stefanha-thinkpad.redhat.com> <20121205183130.GA26052@inetric.com> <20121218134420.GC6697@stefanha-thinkpad.redhat.com> <50D097D6.1020008@msgid.tls.msk.ru> <20121218173422.GA16762@inetric.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20121218173422.GA16762@inetric.com> Subject: Re: [Qemu-devel] [PATCH] e1000: Discard oversized packets based on SBP|LPE List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Michael Contreras Cc: Stefan Hajnoczi , kangli@virtualdevicetech.com, Michael Tokarev , qemu-devel , Anthony Liguori , Andreas Faerber On Tue, Dec 18, 2012 at 12:34:22PM -0500, Michael Contreras wrote: > On Tue, Dec 18, 2012 at 05:49:16PM +0100, Stefan Hajnoczi wrote: > > On Tue, Dec 18, 2012 at 5:20 PM, Michael Tokarev wrote: > > > On 18.12.2012 17:44, Stefan Hajnoczi wrote: > > >> On Wed, Dec 05, 2012 at 01:31:30PM -0500, Michael Contreras wrote: > > >>> Discard packets longer than 16384 when !SBP to match the hardware behavior. > > >>> > > >>> Signed-off-by: Michael Contreras > > >>> --- > > >>> hw/e1000.c | 7 +++++-- > > >>> 1 file changed, 5 insertions(+), 2 deletions(-) > > > > > > It looks like another very good candidate for -stable (up to quite some > > > releases of qemu ago), together with the previous similar patch. > > > > Yes, it's good for -stable. > > > > Stefan > > Thanks guys. Any update on the CVE number? Seems the KVM qemu git tree > still has this vulnerability. Xen has the fix in their qemu unstable > git mirror, but hasn't applied it yet either. Your original LPE patch went into QEMU 1.3. qemu-kvm.git is no longer relevant - it has been merged back into qemu.git and has therefore not been updated since October 11. Use qemu.git. Perhaps others can provide info on the CVE and Xen. Stefan