[PATCH] cryptodev: reject queue counts above the array limit

GuoHan Zhao <[email protected]>
Newsgroups gmane.comp.emulators.qemu
Message-ID <[email protected]>
The queues property accepts any non-zero uint32_t, but
CryptoDevBackendPeers::ccs only has MAX_CRYPTO_QUEUE_NUM entries.

This can make even an error path crash.  For example, a builtin backend
with queues=65 first reports that it only supports one queue.  When the
half-created object is finalized, cleanup walks all 65 entries and reads
ccs[64].

Reject queue counts that do not fit in ccs[].

Fixes: 46fd17054548 ("cryptodev: introduce a new is_used property")
Signed-off-by: GuoHan Zhao <[email protected]>
---
 backends/cryptodev.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/backends/cryptodev.c b/backends/cryptodev.c
index e8f2b18f2017..84f00313e925 100644
--- a/backends/cryptodev.c
+++ b/backends/cryptodev.c
@@ -309,9 +309,9 @@ cryptodev_backend_set_queues(Object *obj, Visitor *v, const char *name,
     if (!visit_type_uint32(v, name, &value, errp)) {
         return;
     }
-    if (!value) {
-        error_setg(errp, "Property '%s.%s' doesn't take value '%" PRIu32 "'",
-                   object_get_typename(obj), name, value);
+    if (!value || value > MAX_CRYPTO_QUEUE_NUM) {
+        error_setg(errp, "Property '%s.%s' must be between 1 and %d",
+                   object_get_typename(obj), name, MAX_CRYPTO_QUEUE_NUM);
         return;
     }
     backend->conf.peers.queues = value;
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.