|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [Xen-devel] [PATCH] x86/32on64: properly honor add-to-physmap-batch's size
Commit 407a3c00ff ("compat/memory: fix build with old gcc") "fixed" a
build issue by switching to the use of uninitialized data. Due to
- the bounding of the uninitialized data item
- the accessed area being outside of Xen space
- arguments being properly verified by the native hypercall function
this is not a security issue.
Reported-by: Marek Marczykowski-Górecki <marmarek@xxxxxxxxxxxxxxxxxxxxxx>
Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>
--- a/xen/common/compat/memory.c
+++ b/xen/common/compat/memory.c
@@ -251,7 +251,7 @@ int compat_memory_op(unsigned int cmd, X
unsigned int limit = (COMPAT_ARG_XLAT_SIZE - sizeof(*nat.atpb))
/ (sizeof(nat.atpb->idxs.p) +
sizeof(nat.atpb->gpfns.p));
/* Use an intermediate variable to suppress warnings on old gcc: */
- unsigned int size = cmp.atpb.size;
+ unsigned int size;
xen_ulong_t *idxs = (void *)(nat.atpb + 1);
xen_pfn_t *gpfns = (void *)(idxs + limit);
/*
@@ -262,8 +262,10 @@ int compat_memory_op(unsigned int cmd, X
enum XLAT_add_to_physmap_batch_u u =
XLAT_add_to_physmap_batch_u_res0;
- if ( copy_from_guest(&cmp.atpb, compat, 1) ||
- !compat_handle_okay(cmp.atpb.idxs, size) ||
+ if ( copy_from_guest(&cmp.atpb, compat, 1) )
+ return -EFAULT;
+ size = cmp.atpb.size;
+ if ( !compat_handle_okay(cmp.atpb.idxs, size) ||
!compat_handle_okay(cmp.atpb.gpfns, size) ||
!compat_handle_okay(cmp.atpb.errs, size) )
return -EFAULT;
Attachment:
x86-32on64-atpb-size.patch _______________________________________________ Xen-devel mailing list Xen-devel@xxxxxxxxxxxxx https://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |