Re: [PATCH] hw/arm/ax3000-soc: fix heap overflow from missing class_size
Peter Maydell <[email protected]>
| Newsgroups | org.nongnu.qemu-devel |
|---|---|
| Message-ID | <CAFEAcA8Tynp5mqj9rRip-Ws-d6=e-kVb0BkZQ2BX=GmLVbK1GA@mail.gmail.com> |
On Mon, 17 Aug 2026 at 22:30, Doug Cook (WINDOWS) <[email protected]> wrote: > > TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and > ax3000_class_init() writes to it: > > Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc); > sc->num_cpus = AX3000_NUM_CPUS; > > but its TypeInfo omits .class_size, so type_initialize() only allocates > class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass). > The store to sc->num_cpus therefore writes 4 bytes of the value 4 just > past the end of the class allocation, corrupting whatever heap block > follows it. > > Fix by setting class_size. > > Fixes: 33a71a68c6e1 ("hw/arm: Add Axiado SoC AX3000") > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197 > Signed-off-by: Doug Cook <[email protected]> > --- Applied to target-arm.next, thanks. I took the liberty of fixing up the Author line to match your Signed-off-by: (i.e. removing the "(WINDOWS)" tag. Let me know if you'd prefer otherwise. -- PMM