Re: [PATCH] hw/arm/ax3000-soc: fix heap overflow from missing class_size

Peter Maydell <[email protected]>
Newsgroups org.nongnu.qemu-devel
Message-ID <CAFEAcA8Tynp5mqj9rRip-Ws-d6=e-kVb0BkZQ2BX=GmLVbK1GA@mail.gmail.com>
On Mon, 17 Aug 2026 at 22:30, Doug Cook (WINDOWS) <[email protected]> wrote:
>
> TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and
> ax3000_class_init() writes to it:
>
>     Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc);
>     sc->num_cpus = AX3000_NUM_CPUS;
>
> but its TypeInfo omits .class_size, so type_initialize() only allocates
> class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass).
> The store to sc->num_cpus therefore writes 4 bytes of the value 4 just
> past the end of the class allocation, corrupting whatever heap block
> follows it.
>
> Fix by setting class_size.
>
> Fixes: 33a71a68c6e1 ("hw/arm: Add Axiado SoC AX3000")
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197
> Signed-off-by: Doug Cook <[email protected]>
> ---

Applied to target-arm.next, thanks. I took the liberty of fixing
up the Author line to match your Signed-off-by: (i.e. removing
the "(WINDOWS)" tag. Let me know if you'd prefer otherwise.

-- PMM
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.