From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:34413) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bDDWB-0007wR-Cy for qemu-devel@nongnu.org; Wed, 15 Jun 2016 12:18:16 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bDDWA-0004WG-In for qemu-devel@nongnu.org; Wed, 15 Jun 2016 12:18:15 -0400 Received: from mx1.redhat.com ([209.132.183.28]:37317) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bDDWA-0004WC-D9 for qemu-devel@nongnu.org; Wed, 15 Jun 2016 12:18:14 -0400 Date: Wed, 15 Jun 2016 21:48:07 +0530 (IST) From: P J P In-Reply-To: <13f61979-7f38-4b33-9160-ea35dfa6bc7f@redhat.com> Message-ID: References: <1465982948-14639-1-git-send-email-ppandit@redhat.com> <7cdb718e-6551-bf3a-a431-575aa29ac767@redhat.com> <13f61979-7f38-4b33-9160-ea35dfa6bc7f@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Subject: Re: [Qemu-devel] [PATCH] scsi: esp: check length before dma read List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Paolo Bonzini Cc: Laszlo Ersek , Qemu Developers , Li Qiang +-- On Wed, 15 Jun 2016, Paolo Bonzini wrote --+ | So a better fix is to change cmdbuf[] to 32 bytes in | include/hw/scsi/esp.h, and define a constant ESP_CMDBUF_SZ equal to 32 | that can be used in handle_ti and in the definition of cmdbuf. Sent a revised patch v3. Thank you. -- Prasad J Pandit / Red Hat Product Security Team 47AF CE69 3A90 54AA 9045 1053 DD13 3D32 FE5B 041F