7d6d5ba
From 0ab680f08208afe51ad6ddc1018b7d6f8b851840 Mon Sep 17 00:00:00 2001
7d6d5ba
From: Adam Jackson <ajax@redhat.com>
7d6d5ba
Date: Thu, 24 Feb 2011 16:06:34 -0500
7d6d5ba
Subject: [PATCH] vbe: Fix malloc size bug
7d6d5ba
7d6d5ba
v2: Slightly more obvious sizing math.
7d6d5ba
7d6d5ba
==14882== Invalid write of size 2
7d6d5ba
==14882==    at 0x6750267: VBEGetVBEInfo (vbe.c:400)
7d6d5ba
==14882==    by 0x6142064: ??? (in /usr/lib64/xorg/modules/drivers/vesa_drv.so)
7d6d5ba
==14882==    by 0x471895: InitOutput (xf86Init.c:519)
7d6d5ba
==14882==    by 0x422778: main (main.c:205)
7d6d5ba
==14882==  Address 0x4f32fa8 is 72 bytes inside a block of size 73 alloc'd
7d6d5ba
==14882==    at 0x4A0640D: malloc (vg_replace_malloc.c:236)
7d6d5ba
==14882==    by 0x675024B: VBEGetVBEInfo (vbe.c:398)
7d6d5ba
==14882==    by 0x6142064: ??? (in /usr/lib64/xorg/modules/drivers/vesa_drv.so)
7d6d5ba
==14882==    by 0x471895: InitOutput (xf86Init.c:519)
7d6d5ba
==14882==    by 0x422778: main (main.c:205)
7d6d5ba
7d6d5ba
Reviewed-by: Mark Kettenis <kettenis@openbsd.org>
7d6d5ba
Reviewed-by: Alan Coopersmith <alan.coopersmith@oracle.com>
7d6d5ba
Signed-off-by: Adam Jackson <ajax@redhat.com>
7d6d5ba
(cherry picked from commit d8caa782009abf4dc17b945e325e83fda299a534)
7d6d5ba
---
7d6d5ba
 hw/xfree86/vbe/vbe.c |    2 +-
7d6d5ba
 1 files changed, 1 insertions(+), 1 deletions(-)
7d6d5ba
7d6d5ba
diff --git a/hw/xfree86/vbe/vbe.c b/hw/xfree86/vbe/vbe.c
7d6d5ba
index bcda5ec..04132d9 100644
7d6d5ba
--- a/hw/xfree86/vbe/vbe.c
7d6d5ba
+++ b/hw/xfree86/vbe/vbe.c
7d6d5ba
@@ -395,7 +395,7 @@ VBEGetVBEInfo(vbeInfoPtr pVbe)
7d6d5ba
     i = 0;
7d6d5ba
     while (modes[i] != 0xffff)
7d6d5ba
 	i++;
7d6d5ba
-    block->VideoModePtr = malloc(sizeof(CARD16) * i + 1);
7d6d5ba
+    block->VideoModePtr = malloc(sizeof(CARD16) * (i + 1));
7d6d5ba
     memcpy(block->VideoModePtr, modes, sizeof(CARD16) * i);
7d6d5ba
     block->VideoModePtr[i] = 0xffff;
7d6d5ba
 
7d6d5ba
-- 
7d6d5ba
1.7.4
7d6d5ba