From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:52600) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1V75HF-0008AD-4a for qemu-devel@nongnu.org; Wed, 07 Aug 2013 11:04:01 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1V75H6-0007Rg-8W for qemu-devel@nongnu.org; Wed, 07 Aug 2013 11:03:53 -0400 Received: from e38.co.us.ibm.com ([32.97.110.159]:55325) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1V75H6-0007R4-1v for qemu-devel@nongnu.org; Wed, 07 Aug 2013 11:03:44 -0400 Received: from /spool/local by e38.co.us.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Wed, 7 Aug 2013 09:03:39 -0600 Received: from d03relay04.boulder.ibm.com (d03relay04.boulder.ibm.com [9.17.195.106]) by d03dlp03.boulder.ibm.com (Postfix) with ESMTP id A3E8119D8053 for ; Wed, 7 Aug 2013 09:02:54 -0600 (MDT) Received: from d03av05.boulder.ibm.com (d03av05.boulder.ibm.com [9.17.195.85]) by d03relay04.boulder.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id r77F2xER343424 for ; Wed, 7 Aug 2013 09:03:03 -0600 Received: from d03av05.boulder.ibm.com (loopback [127.0.0.1]) by d03av05.boulder.ibm.com (8.14.4/8.13.1/NCO v10.0 AVout) with ESMTP id r77F2mEh029579 for ; Wed, 7 Aug 2013 09:02:48 -0600 Message-ID: <52026193.8010307@linux.vnet.ibm.com> Date: Wed, 07 Aug 2013 11:02:43 -0400 From: "Michael R. Hines" MIME-Version: 1.0 References: In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH 0/3] rdma: validate remote provided RDMAControlHeader::len List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Isaku Yamahata Cc: owasserm@redhat.com, quintela@redhat.com, mrhines@us.ibm.com, qemu-devel@nongnu.org, pbonzini@redhat.com On 08/06/2013 10:26 PM, Isaku Yamahata wrote: > RDMAControlHeader::len is remote-provided. So validate the value before use. > > Isaku Yamahata (3): > rdma: use resp.len after validation in qemu_rdma_registration_stop > rdma: validate RDMAControlHeader::len > rdma: check if RDMAControlHeader::len match transferred byte > > migration-rdma.c | 44 ++++++++++++++++++++++++++++++-------------- > 1 file changed, 30 insertions(+), 14 deletions(-) > Thank you. I will apply to my tree and re-send. - Michael