[Stable-11.1.1 17/42] s390x/ipl: validate num_comp against iplb length before iterating

Michael Tokarev <[email protected]>
Newsgroups gmane.comp.emulators.qemu,gmane.comp.emulators.qemu.stable
Message-ID <[email protected]>
From: Joshua Daley <[email protected]>

In ipl_valid_pv_components(), the upper bound of the for loop,
ipib_pv->num_comp, is read from guest memory. Before iterating, verify
that its value will not cause a read beyond the end of the
IplParameterBlock.

Fixes: c3347ed0d2ee42a7 ("s390x: protvirt: Support unpack facility")
Cc: [email protected]
Signed-off-by: Joshua Daley <[email protected]>
Reviewed-by: Christian Borntraeger <[email protected]>
Reviewed-by: Matthew Rosato <[email protected]>
Reviewed-by: Eric Farman <[email protected]>
Link: https://lore.kernel.org/qemu-devel/[email protected]
[[email protected]: Added qemu-stable]
Signed-off-by: Eric Farman <[email protected]>
(cherry picked from commit df607fd056044e40352a43f0b4422b9a5cb015c8)
Signed-off-by: Michael Tokarev <[email protected]>

diff --git a/hw/s390x/ipl.h b/hw/s390x/ipl.h
index fac30763df2..ef9c063d904 100644
--- a/hw/s390x/ipl.h
+++ b/hw/s390x/ipl.h
@@ -124,6 +124,12 @@ static inline bool ipl_valid_pv_components(IplParameterBlock *iplb)
         return false;
     }
 
+    if (offsetof(IplParameterBlock, pv.components) +
+        ipib_pv->num_comp * sizeof(IPLBlockPVComp) >
+        be32_to_cpu(iplb->len)) {
+        return false;
+    }
+
     for (i = 0; i < ipib_pv->num_comp; i++) {
         /* Addr must be 4k aligned */
         if (ipib_pv->components[i].addr & ~TARGET_PAGE_MASK) {
-- 
2.47.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.