]> git.proxmox.com Git - mirror_edk2.git/commitdiff
OvmfPkg/QemuVideoDxe: avoid arithmetic on null pointer
authorLaszlo Ersek <lersek@redhat.com>
Fri, 12 Apr 2019 14:13:48 +0000 (16:13 +0200)
committerLaszlo Ersek <lersek@redhat.com>
Thu, 18 Apr 2019 14:03:38 +0000 (16:03 +0200)
The real mode interrupt vector table, which we modify for the sake of
Windows 7, starts at address 0, which happens to be the representation of
null pointers on all edk2 architectures. A null pointer may never undergo
pointer arithmetic, and RH covscan justifiedly reports:

> Error: CPPCHECK_WARNING (CWE-682):
> edk2-89910a39dcfd/OvmfPkg/QemuVideoDxe/VbeShim.c:105:
> error[nullPointerArithmetic]: Pointer addition with NULL pointer.
> #  103|     //
> #  104|     Segment0Pages = 1;
> #  105|->   Int0x10       = (IVT_ENTRY *)(UINTN)Segment0 + 0x10;
> #  106|     Segment0AllocationStatus = gBS->AllocatePages (
> #  107|                                       AllocateAddress,

Fix this by calculating the EFI_PHYSICAL_ADDRESS of IVT entry 0x10 first,
and by casting the address to the right type second.

Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org>
Cc: Jordan Justen <jordan.l.justen@intel.com>
Bugzilla: https://bugzilla.tianocore.org/show_bug.cgi?id=1710
Issue: scan-1002.txt
Signed-off-by: Laszlo Ersek <lersek@redhat.com>
Acked-by: Ard Biesheuvel <ard.biesheuvel@linaro.org>
OvmfPkg/QemuVideoDxe/VbeShim.c

index 69081f09e6302e5eb59dc38af266a251edae2246..c23dc984d4538f0b955ecddff465d0b7829ce9eb 100644 (file)
@@ -96,7 +96,7 @@ InstallVbeShim (
   // The allocation request may fail, eg. if LegacyBiosDxe has already run.\r
   //\r
   Segment0Pages = 1;\r
-  Int0x10       = (IVT_ENTRY *)(UINTN)Segment0 + 0x10;\r
+  Int0x10       = (IVT_ENTRY *)(UINTN)(Segment0 + 0x10 * sizeof (IVT_ENTRY));\r
   Segment0AllocationStatus = gBS->AllocatePages (\r
                                     AllocateAddress,\r
                                     EfiBootServicesCode,\r