qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Jason Wang <jasowang@redhat.com>
To: Peter Maydell <peter.maydell@linaro.org>,
	Mauro Matteo Cascella <mcascell@redhat.com>
Cc: Rob Herring <robh@kernel.org>, qemu-arm <qemu-arm@nongnu.org>,
	QEMU Developers <qemu-devel@nongnu.org>,
	ziming zhang <ezrakiez@gmail.com>
Subject: Re: [PATCH] hw/net/xgmac: Fix buffer overflow in xgmac_enet_send()
Date: Tue, 14 Jul 2020 17:09:23 +0800	[thread overview]
Message-ID: <df0eae88-2bc8-04fa-feb9-7633ba13d635@redhat.com> (raw)
In-Reply-To: <CAFEAcA9XQUcdiy2x18Zr+EYDaJ4hY-1Bd-DgL6-j6sJi5Ow+Gg@mail.gmail.com>


On 2020/7/10 下午7:07, Peter Maydell wrote:
> On Fri, 10 Jul 2020 at 10:20, Mauro Matteo Cascella <mcascell@redhat.com> wrote:
>> A buffer overflow issue was reported by Mr. Ziming Zhang, CC'd here. It
>> occurs while sending an Ethernet frame due to missing break statements
>> and improper checking of the buffer size.
>>
>> Reported-by: Ziming Zhang <ezrakiez@gmail.com>
>> Signed-off-by: Mauro Matteo Cascella <mcascell@redhat.com>
>> ---
>>   hw/net/xgmac.c | 7 +++++--
>>   1 file changed, 5 insertions(+), 2 deletions(-)
>>
>> diff --git a/hw/net/xgmac.c b/hw/net/xgmac.c
>> index 574dd47b41..b872afbb1a 100644
>> --- a/hw/net/xgmac.c
>> +++ b/hw/net/xgmac.c
>> @@ -224,17 +224,20 @@ static void xgmac_enet_send(XgmacState *s)
>>               DEBUGF_BRK("qemu:%s:ERROR...ERROR...ERROR... -- "
>>                           "xgmac buffer 1 len on send > 2048 (0x%x)\n",
>>                            __func__, bd.buffer1_size & 0xfff);
>> +            break;
>>           }
>>           if ((bd.buffer2_size & 0xfff) != 0) {
>>               DEBUGF_BRK("qemu:%s:ERROR...ERROR...ERROR... -- "
>>                           "xgmac buffer 2 len on send != 0 (0x%x)\n",
>>                           __func__, bd.buffer2_size & 0xfff);
>> +            break;
>>           }
>> -        if (len >= sizeof(frame)) {
>> +        if (frame_size + len >= sizeof(frame)) {
>>               DEBUGF_BRK("qemu:%s: buffer overflow %d read into %zu "
>> -                        "buffer\n" , __func__, len, sizeof(frame));
>> +                        "buffer\n" , __func__, frame_size + len, sizeof(frame));
>>               DEBUGF_BRK("qemu:%s: buffer1.size=%d; buffer2.size=%d\n",
>>                           __func__, bd.buffer1_size, bd.buffer2_size);
>> +            break;
>>           }
>>
>>           cpu_physical_memory_read(bd.buffer1_addr, ptr, len);
> This is correct in the sense that it avoids the buffer overflow.
>
> I suspect that we should probably also be reporting the error
> back to the guest via some kind of error flag in the descriptor
> and/or in a status register. Unfortunately I don't have a copy
> of the datasheet and it doesn't seem to be available online :-(
> Does anybody have a copy to check ?
>
> thanks
> -- PMM


I tried to download the datasheet from [1] but it's not a programmer 
manual.

I think we can apply this patch first and do follow-up fixes on top?

Thanks

[1] https://www.synopsys.com/dw/ipdir.php?ds=dwc_ether_xgmac


>



  reply	other threads:[~2020-07-14  9:10 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-07-10  9:19 [PATCH] hw/net/xgmac: Fix buffer overflow in xgmac_enet_send() Mauro Matteo Cascella
2020-07-10 11:07 ` Peter Maydell
2020-07-14  9:09   ` Jason Wang [this message]
2020-07-20  9:14     ` Peter Maydell
2020-07-20  9:27       ` Jason Wang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=df0eae88-2bc8-04fa-feb9-7633ba13d635@redhat.com \
    --to=jasowang@redhat.com \
    --cc=ezrakiez@gmail.com \
    --cc=mcascell@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=robh@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).