Searched hist:"5 f691ff9" (Results 1 – 1 of 1) sorted by relevance
/qemu/hw/pci/ |
H A D | pcie_aer.c | diff 5f691ff9 Thu Apr 03 16:51:31 GMT 2014 Michael S. Tsirkin <mst@redhat.com> hw/pci/pcie_aer.c: fix buffer overruns on invalid state load
4) CVE-2013-4529 hw/pci/pcie_aer.c pcie aer log can overrun the buffer if log_num is too large
There are two issues in this file: 1. log_max from remote can be larger than on local then buffer will overrun with data coming from state file. 2. log_num can be larger then we get data corruption again with an overflow but not adversary controlled.
Fix both issues.
Reported-by: Anthony Liguori <anthony@codemonkey.ws> Reported-by: Michael S. Tsirkin <mst@redhat.com> Signed-off-by: Michael S. Tsirkin <mst@redhat.com> Reviewed-by: Dr. David Alan Gilbert <dgilbert@redhat.com> Signed-off-by: Juan Quintela <quintela@redhat.com>
|