qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [PATCH] cryptodev-vhost-user: fix a oob access


From: Gonglei (Arei)
Subject: Re: [Qemu-devel] [PATCH] cryptodev-vhost-user: fix a oob access
Date: Mon, 18 Mar 2019 01:03:03 +0000

Hi,

> -----Original Message-----
> From: Li Qiang [mailto:address@hidden
> Sent: Sunday, March 17, 2019 5:10 PM
> To: Gonglei (Arei) <address@hidden>
> Cc: address@hidden; Li Qiang <address@hidden>
> Subject: [PATCH] cryptodev-vhost-user: fix a oob access
> 
> The 'queue_index' of create/close_session function
> is from guest and can be exceed 'MAX_CRYPTO_QUEUE_NUM'.
> This leads oob access. This patch avoid this.
> 
> Signed-off-by: Li Qiang <address@hidden>
> ---
>  backends/cryptodev-vhost-user.c | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/backends/cryptodev-vhost-user.c b/backends/cryptodev-vhost-user.c
> index 1052a5d0e9..36a40eeb4d 100644
> --- a/backends/cryptodev-vhost-user.c
> +++ b/backends/cryptodev-vhost-user.c
> @@ -236,6 +236,8 @@ static int64_t
> cryptodev_vhost_user_sym_create_session(
>             CryptoDevBackendSymSessionInfo *sess_info,
>             uint32_t queue_index, Error **errp)
>  {
> +    assert(queue_index < MAX_CRYPTO_QUEUE_NUM);
> +
>      CryptoDevBackendClient *cc =
>                     backend->conf.peers.ccs[queue_index];
>      CryptoDevBackendVhost *vhost_crypto;
> @@ -262,6 +264,8 @@ static int cryptodev_vhost_user_sym_close_session(
>             uint64_t session_id,
>             uint32_t queue_index, Error **errp)
>  {
> +    assert(queue_index < MAX_CRYPTO_QUEUE_NUM);
> +
>      CryptoDevBackendClient *cc =
>                    backend->conf.peers.ccs[queue_index];
>      CryptoDevBackendVhost *vhost_crypto;
> --
> 2.17.1
> 

Pls add an assertion for cryptodev-builtin backend though the queue_index 
isn't used currently.

Thanks,
-Gonglei




reply via email to

[Prev in Thread] Current Thread [Next in Thread]