]>
Commit | Line | Data |
---|---|---|
06fb0513 WB |
1 | From aafca5995f11e0cd69e0607bfb7b3b7333f96be8 Mon Sep 17 00:00:00 2001 |
2 | From: Gerd Hoffmann <kraxel@redhat.com> | |
3 | Date: Mon, 30 May 2016 09:09:19 +0200 | |
4 | Subject: [PATCH 5/9] vmsvga: add more fifo checks | |
5 | MIME-Version: 1.0 | |
6 | Content-Type: text/plain; charset=UTF-8 | |
7 | Content-Transfer-Encoding: 8bit | |
8 | ||
9 | Make sure all fifo ptrs are within range. | |
10 | ||
11 | Fixes: CVE-2016-4454 | |
12 | Cc: P J P <ppandit@redhat.com> | |
13 | Reported-by: 李强 <liqiang6-s@360.cn> | |
14 | Signed-off-by: Gerd Hoffmann <kraxel@redhat.com> | |
15 | --- | |
16 | hw/display/vmware_vga.c | 5 ++++- | |
17 | 1 file changed, 4 insertions(+), 1 deletion(-) | |
18 | ||
19 | diff --git a/hw/display/vmware_vga.c b/hw/display/vmware_vga.c | |
20 | index 3ce1717..f2663ee 100644 | |
21 | --- a/hw/display/vmware_vga.c | |
22 | +++ b/hw/display/vmware_vga.c | |
23 | @@ -561,7 +561,10 @@ static inline int vmsvga_fifo_length(struct vmsvga_state_s *s) | |
24 | if (CMD(min) < (uint8_t *) s->cmd->fifo - (uint8_t *) s->fifo) { | |
25 | return 0; | |
26 | } | |
27 | - if (CMD(max) > SVGA_FIFO_SIZE) { | |
28 | + if (CMD(max) > SVGA_FIFO_SIZE || | |
29 | + CMD(min) >= SVGA_FIFO_SIZE || | |
30 | + CMD(stop) >= SVGA_FIFO_SIZE || | |
31 | + CMD(next_cmd) >= SVGA_FIFO_SIZE) { | |
32 | return 0; | |
33 | } | |
34 | if (CMD(max) < CMD(min) + 10 * 1024) { | |
35 | -- | |
36 | 2.1.4 | |
37 |