|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
From 215902d7b6fb50c6fc216fc74f770858278ed904 Mon Sep 17 00:00:00 2001
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
From: hangaohuai <hangaohuai@huawei.com>
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
Date: Tue, 14 Mar 2017 14:39:19 +0800
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
Subject: [PATCH] fix :cirrus_vga fix OOB read case qemu Segmentation fault
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
check the validity of parameters in cirrus_bitblt_rop_fwd_transp_xxx
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
and cirrus_bitblt_rop_fwd_xxx to avoid the OOB read which causes qemu Segmentation fault.
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
After the fix, we will touch the assert in
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
cirrus_invalidate_region:
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
assert(off_cur_end >= off_cur);
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
Signed-off-by: fangying <fangying1@huawei.com>
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
Signed-off-by: hangaohuai <hangaohuai@huawei.com>
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
Message-id: 20170314063919.16200-1-hangaohuai@huawei.com
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
---
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
hw/cirrus_vga_rop.h | 10 ++++++++++
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
1 file changed, 10 insertions(+)
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
diff --git a/hw/cirrus_vga_rop.h b/hw/cirrus_vga_rop.h
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
index 0925a00..b7447f8 100644
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
--- a/hw/cirrus_vga_rop.h
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+++ b/hw/cirrus_vga_rop.h
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
@@ -97,6 +97,11 @@ glue(glue(cirrus_bitblt_rop_fwd_transp_, ROP_NAME),_8)(CirrusVGAState *s,
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
src = src_ - src_base;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
dstpitch -= bltwidth;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
srcpitch -= bltwidth;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+ if (bltheight > 1 && (dstpitch < 0 || srcpitch < 0)) {
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+ return;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+ }
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
for (y = 0; y < bltheight; y++) {
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
for (x = 0; x < bltwidth; x++) {
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
p = *(dst_base + m(dst));
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
@@ -143,6 +148,11 @@ glue(glue(cirrus_bitblt_rop_fwd_transp_, ROP_NAME),_16)(CirrusVGAState *s,
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
src = src_ - src_base;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
dstpitch -= bltwidth;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
srcpitch -= bltwidth;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+ if (bltheight > 1 && (dstpitch < 0 || srcpitch < 0)) {
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+ return;
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+ }
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
+
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
for (y = 0; y < bltheight; y++) {
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
for (x = 0; x < bltwidth; x+=2) {
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
p1 = *(dst_base + m(dst));
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
--
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
1.8.3.1
|
|
![](https://seccdn.libravatar.org/avatar/f1a0ddfc363b14e167bf8548e95f340032d1964ae5b6ea4f235e351fd948008e?s=16&d=retro) |
ee3a555 |
|