qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH 0/1] Add check for header length in virtio-net-tx
@ 2019-07-16  3:38 Oleinik, Alexander
  2019-07-16  3:38 ` [Qemu-devel] [PATCH 1/1] virtio-net: check guest header length is valid Oleinik, Alexander
  2019-07-16  8:14 ` [Qemu-devel] [PATCH 0/1] Add check for header length in virtio-net-tx Michael S. Tsirkin
  0 siblings, 2 replies; 4+ messages in thread
From: Oleinik, Alexander @ 2019-07-16  3:38 UTC (permalink / raw)
  To: qemu-devel@nongnu.org
  Cc: mst@redhat.com, jasowang@redhat.com, Oleinik, Alexander,
	bsd@redhat.com, stefanha@redhat.com, pbonzini@redhat.com

While fuzzing the virtio-net tx vq, I ran into an assertion failure due
to iov_copy offsets larger than the total iov size. Though there is
a check to cover this, it does not execute when !n->has_vnet_hdr. This
patch tries to fix this. 

The call stack for the assertion failure:

#8 in __assert_fail (libc.so.6+0x300f1)
#9 in iov_copy iov.c:266:5
#10 in virtio_net_flush_tx virtio-net.c:2073:23
#11 in virtio_net_tx_bh virtio-net.c:2197:11
#12 in aio_bh_poll async.c:118:13
#13 in aio_dispatch aio-posix.c:460:5
#14 in aio_ctx_dispatch async.c:261:5
#15 in g_main_context_dispatch (libglib-2.0.so.0+0x4df2d)
#16 in glib_pollfds_poll main-loop.c:213:9
#17 in os_host_main_loop_wait main-loop.c:236
#18 in main_loop_wait main-loop.c:512
#19 in virtio_net_tx_fuzz virtio-net-fuzz.c:160:3

Thanks
-Alex

Alexander Oleinik (1):
  virtio-net: check guest header length is valid

 hw/net/virtio-net.c | 13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

-- 
2.20.1



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2019-07-16  8:14 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-07-16  3:38 [Qemu-devel] [PATCH 0/1] Add check for header length in virtio-net-tx Oleinik, Alexander
2019-07-16  3:38 ` [Qemu-devel] [PATCH 1/1] virtio-net: check guest header length is valid Oleinik, Alexander
2019-07-16  8:01   ` Michael S. Tsirkin
2019-07-16  8:14 ` [Qemu-devel] [PATCH 0/1] Add check for header length in virtio-net-tx Michael S. Tsirkin

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).