[Stable-11.1.1 17/42] s390x/ipl: validate num_comp against iplb length before iterating
Michael Tokarev <[email protected]>
| Newsgroups | gmane.comp.emulators.qemu,gmane.comp.emulators.qemu.stable |
|---|---|
| Message-ID | <[email protected]> |
From: Joshua Daley <[email protected]> In ipl_valid_pv_components(), the upper bound of the for loop, ipib_pv->num_comp, is read from guest memory. Before iterating, verify that its value will not cause a read beyond the end of the IplParameterBlock. Fixes: c3347ed0d2ee42a7 ("s390x: protvirt: Support unpack facility") Cc: [email protected] Signed-off-by: Joshua Daley <[email protected]> Reviewed-by: Christian Borntraeger <[email protected]> Reviewed-by: Matthew Rosato <[email protected]> Reviewed-by: Eric Farman <[email protected]> Link: https://lore.kernel.org/qemu-devel/[email protected] [[email protected]: Added qemu-stable] Signed-off-by: Eric Farman <[email protected]> (cherry picked from commit df607fd056044e40352a43f0b4422b9a5cb015c8) Signed-off-by: Michael Tokarev <[email protected]> diff --git a/hw/s390x/ipl.h b/hw/s390x/ipl.h index fac30763df2..ef9c063d904 100644 --- a/hw/s390x/ipl.h +++ b/hw/s390x/ipl.h @@ -124,6 +124,12 @@ static inline bool ipl_valid_pv_components(IplParameterBlock *iplb) return false; } + if (offsetof(IplParameterBlock, pv.components) + + ipib_pv->num_comp * sizeof(IPLBlockPVComp) > + be32_to_cpu(iplb->len)) { + return false; + } + for (i = 0; i < ipib_pv->num_comp; i++) { /* Addr must be 4k aligned */ if (ipib_pv->components[i].addr & ~TARGET_PAGE_MASK) { -- 2.47.3