[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-devel] [PATCH] x86/HVM: fix boundary check in hvmemul_insn_fetch() (again)

Commit 5a992b670b ("x86/hvm: Fix boundary check in
hvmemul_insn_fetch()") went a little too far in its correction to
commit 0943a03037 ("x86/hvm: Fixes to hvmemul_insn_fetch()"): Keep the
start offset check, but restore the original end offset one.

Signed-off-by: Jan Beulich <jbeulich@xxxxxxxx>

--- a/xen/arch/x86/hvm/emulate.c
+++ b/xen/arch/x86/hvm/emulate.c
@@ -959,7 +959,7 @@ int hvmemul_insn_fetch(
              * which means something went wrong with instruction decoding...
             if ( insn_off >= sizeof(hvmemul_ctxt->insn_buf) ||
-                 (insn_off + bytes) >= sizeof(hvmemul_ctxt->insn_buf) )
+                 insn_off + bytes > sizeof(hvmemul_ctxt->insn_buf) )
                 return X86EMUL_UNHANDLEABLE;

Xen-devel mailing list



Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.