summaryrefslogtreecommitdiffstats
path: root/scripts/git-submodule.sh
diff options
context:
space:
mode:
authorPrasad J Pandit2018-10-26 21:43:14 +0200
committerPaolo Bonzini2018-11-06 21:35:05 +0100
commite58ccf039650065a9442de43c9816f81e88f27f6 (patch)
tree5f5849f8c32a89d97a874594c7c335074ab227a9 /scripts/git-submodule.sh
parentscripts/dump-guest-memory: Synchronize with guest_phys_blocks_region_add (diff)
downloadqemu-e58ccf039650065a9442de43c9816f81e88f27f6.tar.gz
qemu-e58ccf039650065a9442de43c9816f81e88f27f6.tar.xz
qemu-e58ccf039650065a9442de43c9816f81e88f27f6.zip
lsi53c895a: check message length value is valid
While writing a message in 'lsi_do_msgin', message length value in 'msg_len' could be invalid due to an invalid migration stream. Add an assertion to avoid an out of bounds access, and reject the incoming migration data if it contains an invalid message length. Discovered by Deja vu Security. Reported by Oracle. Signed-off-by: Prasad J Pandit <pjp@fedoraproject.org> Message-Id: <20181026194314.18663-1-ppandit@redhat.com> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Diffstat (limited to 'scripts/git-submodule.sh')
0 files changed, 0 insertions, 0 deletions