qemu/hw/char
Michael S. Tsirkin 5eb0b194e9 cadence_uart: bounds check write offset
cadence_uart_init() initializes an I/O memory region of size 0x1000
bytes.  However in uart_write(), the 'offset' parameter (offset within
region) is divided by 4 and then used to index the array 'r' of size
CADENCE_UART_R_MAX which is much smaller: (0x48/4).  If 'offset>>=2'
exceeds CADENCE_UART_R_MAX, this will cause an out-of-bounds memory
write where the offset and the value are controlled by guest.

This will corrupt QEMU memory, in most situations this causes the vm to
crash.

Fix by checking the offset against the array size.

Cc: qemu-stable@nongnu.org
Reported-by: 李强 <liqiang6-s@360.cn>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Reviewed-by: Alistair Francis <alistair.francis@xilinx.com>
Message-id: 20160418100735.GA517@redhat.com
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2016-04-19 11:13:59 +01:00
..
bcm2835_aux.c bcm2835_aux: add emulation of BCM2835 AUX (aka UART1) block 2016-03-16 17:42:18 +00:00
cadence_uart.c cadence_uart: bounds check write offset 2016-04-19 11:13:59 +01:00
debugcon.c include/qemu/osdep.h: Don't include qapi/error.h 2016-03-22 22:20:15 +01:00
digic-uart.c arm: Clean up includes 2016-01-29 15:07:23 +00:00
escc.c qapi: Don't special-case simple union wrappers 2016-03-18 10:29:26 +01:00
etraxfs_ser.c hw: Clean up includes 2016-01-29 15:07:25 +00:00
exynos4210_uart.c arm: Clean up includes 2016-01-29 15:07:23 +00:00
grlib_apbuart.c sparc: Clean up includes 2016-01-29 15:07:22 +00:00
imx_serial.c arm: Clean up includes 2016-01-29 15:07:23 +00:00
ipoctal232.c hw: Clean up includes 2016-01-29 15:07:25 +00:00
lm32_juart.c lm32: Clean up includes 2016-01-29 15:07:22 +00:00
lm32_uart.c lm32: Clean up includes 2016-01-29 15:07:22 +00:00
Makefile.objs bcm2835_aux: add emulation of BCM2835 AUX (aka UART1) block 2016-03-16 17:42:18 +00:00
mcf_uart.c hw: Clean up includes 2016-01-29 15:07:25 +00:00
milkymist-uart.c lm32: Clean up includes 2016-01-29 15:07:22 +00:00
omap_uart.c arm devices: Clean up includes 2016-01-29 15:07:25 +00:00
parallel.c include/qemu/osdep.h: Don't include qapi/error.h 2016-03-22 22:20:15 +01:00
pl011.c arm: Clean up includes 2016-01-29 15:07:23 +00:00
sclpconsole-lm.c s390: Clean up includes 2016-01-29 15:07:22 +00:00
sclpconsole.c s390: Clean up includes 2016-01-29 15:07:22 +00:00
serial-isa.c include/qemu/osdep.h: Don't include qapi/error.h 2016-03-22 22:20:15 +01:00
serial-pci.c include/qemu/osdep.h: Don't include qapi/error.h 2016-03-22 22:20:15 +01:00
serial.c Replaced get_tick_per_sec() by NANOSECONDS_PER_SECOND 2016-03-22 22:20:17 +01:00
sh_serial.c hw: Clean up includes 2016-01-29 15:07:25 +00:00
spapr_vty.c hw: explicitly include qemu-common.h and cpu.h 2016-03-22 22:20:17 +01:00
stm32f2xx_usart.c arm devices: Clean up includes 2016-01-29 15:07:25 +00:00
virtio-console.c virtio: Clean up includes 2016-01-29 15:07:23 +00:00
virtio-serial-bus.c include/qemu/osdep.h: Don't include qapi/error.h 2016-03-22 22:20:15 +01:00
xen_console.c xen: Clean up includes 2016-01-29 15:07:23 +00:00
xilinx_uartlite.c arm devices: Clean up includes 2016-01-29 15:07:25 +00:00