Michael S. Tsirkin
d7f053652f
cadence_gem: fix buffer overflow
...
gem_transmit copies a packet from guest into an tx_packet[2048]
array on stack, with size limited by descriptor length set by guest. If
guest is malicious and specifies a descriptor length that is too large,
and should packet size exceed array size, this results in a buffer
overflow.
Reported-by: 刘令 <liuling-it@360.cn >
Signed-off-by: Michael S. Tsirkin <mst@redhat.com >
Signed-off-by: Jason Wang <jasowang@redhat.com >
2016-02-04 13:22:06 +08:00
..
2016-01-29 15:07:23 +00:00
2016-01-29 15:07:22 +00:00
2016-01-29 15:07:23 +00:00
2016-01-21 14:15:07 +00:00
2016-02-02 13:57:31 +01:00
2016-02-02 17:50:46 +01:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:24 +00:00
2016-02-03 10:41:36 +01:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:22 +00:00
2016-01-30 23:37:36 +11:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:22 +00:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:25 +00:00
2016-01-28 11:13:13 +00:00
2016-01-23 14:30:04 +00:00
2016-02-02 13:28:58 +01:00
2016-01-29 15:07:25 +00:00
2016-02-04 13:22:06 +08:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:24 +00:00
2016-01-30 23:37:38 +11:00
2016-01-29 15:07:25 +00:00
2016-01-30 23:49:27 +11:00
2016-01-29 15:07:22 +00:00
2016-02-02 17:50:46 +01:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:22 +00:00
2016-01-29 15:07:22 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:22 +00:00
2016-02-02 14:11:01 +01:00
2016-01-29 15:07:24 +00:00
2016-01-29 15:07:23 +00:00
2016-01-29 15:07:25 +00:00
2016-01-29 15:07:23 +00:00
2016-01-29 15:07:23 +00:00
2016-01-29 15:07:24 +00:00
2015-12-22 18:39:19 +02:00