|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Xen-devel] [PATCH 2/4] arm: add bounds check on hypercall array
On Wed, 25 Jul 2012, Ian Campbell wrote:
> Otherwise a guest can cause us to run off the end of the array.
>
> Signed-off-by: Ian Campbell <ian.campbell@xxxxxxxxxx>
> ---
> xen/arch/arm/traps.c | 6 ++++++
> 1 files changed, 6 insertions(+), 0 deletions(-)
>
> diff --git a/xen/arch/arm/traps.c b/xen/arch/arm/traps.c
> index f2c25b5..6201d38 100644
> --- a/xen/arch/arm/traps.c
> +++ b/xen/arch/arm/traps.c
> @@ -479,6 +479,12 @@ static void do_trap_hypercall(struct cpu_user_regs
> *regs, unsigned long iss)
> return;
> }
>
> + if ( regs->r12 > ARRAY_SIZE(arm_hypercall_table) )
> + {
> + regs->r0 = -ENOSYS;
> + return;
> + }
shouldn't this be >=?
> call = arm_hypercall_table[regs->r12].fn;
> if ( call == NULL )
> {
> --
> 1.7.9.1
>
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |