summaryrefslogtreecommitdiffstats
path: root/include/standard-headers/linux
diff options
context:
space:
mode:
authorLi Qiang2021-05-16 05:04:02 +0200
committerGerd Hoffmann2021-05-27 11:55:59 +0200
commit9f22893adcb02580aee5968f32baa2cd109b3ec2 (patch)
tree0c7ed9e162d074886ac73269a15b677c023a6714 /include/standard-headers/linux
parentvhost-user-gpu: fix memory leak in 'virgl_resource_attach_backing' (CVE-2021-... (diff)
downloadqemu-9f22893adcb02580aee5968f32baa2cd109b3ec2.tar.gz
qemu-9f22893adcb02580aee5968f32baa2cd109b3ec2.tar.xz
qemu-9f22893adcb02580aee5968f32baa2cd109b3ec2.zip
vhost-user-gpu: fix OOB write in 'virgl_cmd_get_capset' (CVE-2021-3546)
If 'virgl_cmd_get_capset' set 'max_size' to 0, the 'virgl_renderer_fill_caps' will write the data after the 'resp'. This patch avoid this by checking the returned 'max_size'. virtio-gpu fix: abd7f08b23 ("display: virtio-gpu-3d: check virgl capabilities max_size") Fixes: CVE-2021-3546 Reported-by: Li Qiang <liq3ea@163.com> Reviewed-by: Prasad J Pandit <pjp@fedoraproject.org> Signed-off-by: Li Qiang <liq3ea@163.com> Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com> Message-Id: <20210516030403.107723-8-liq3ea@163.com> Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Diffstat (limited to 'include/standard-headers/linux')
0 files changed, 0 insertions, 0 deletions