qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH] virtio-balloon: fix buffer overflow in memory stats feature
@ 2014-09-15 18:09 Luiz Capitulino
  2014-09-15 19:16 ` Eric Blake
  2014-09-16  7:25 ` Markus Armbruster
  0 siblings, 2 replies; 7+ messages in thread
From: Luiz Capitulino @ 2014-09-15 18:09 UTC (permalink / raw)
  To: qemu-devel; +Cc: qemu-stable

When a QMP client changes the polling interval time by setting
the guest-stats-polling-interval property, the interval value
is stored and manipuled as an int64_t variable.

However, the balloon_stats_change_timer() function, which is
used to set the actual timer with the interval value, takes
an int instead, causing an overflow for big interval values.

Fix it.

Signed-off-by: Luiz Capitulino <lcapitulino@redhat.com>
---
 hw/virtio/virtio-balloon.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/virtio/virtio-balloon.c b/hw/virtio/virtio-balloon.c
index 2c30b3d..9629264 100644
--- a/hw/virtio/virtio-balloon.c
+++ b/hw/virtio/virtio-balloon.c
@@ -87,7 +87,7 @@ static void balloon_stats_destroy_timer(VirtIOBalloon *s)
     }
 }
 
-static void balloon_stats_change_timer(VirtIOBalloon *s, int secs)
+static void balloon_stats_change_timer(VirtIOBalloon *s, int64_t secs)
 {
     timer_mod(s->stats_timer, qemu_clock_get_ms(QEMU_CLOCK_VIRTUAL) + secs * 1000);
 }
-- 
1.9.3

^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2014-09-16 13:44 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-09-15 18:09 [Qemu-devel] [PATCH] virtio-balloon: fix buffer overflow in memory stats feature Luiz Capitulino
2014-09-15 19:16 ` Eric Blake
2014-09-15 19:33   ` Luiz Capitulino
2014-09-16  7:25 ` Markus Armbruster
2014-09-16 12:34   ` Luiz Capitulino
2014-09-16 13:43     ` Markus Armbruster
2014-09-16 13:44       ` Luiz Capitulino

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).