- target/i386: Introduce SapphireRapids-v3 to add missing features - qtest/fuzz-lsi53c895a-test: set guest RAM to 2G - hw/net/lan9118: Signal TSFL_INT flag when TX FIFO reaches specified level - target/arm: Fix alignment for VLD4.32 - hw/microblaze: pass random seed to fdt - tests/qtest: npcm7xx-emc-test: Skip checking MAC - tests: mark io-command test as skipped if socat is missing - tests: unit: add NULL-pointer check - tests: test-qga: close socket on failure to connect - vdpa:block device capacity expansion online support vdpa block device update capacity. - virtio-net: Ensure queue index fits with RSS(CVE-2024-6505) - nbd/server: CVE-2024-7409: Avoid use-after-free when closing server - ppc/vof: Fix unaligned FDT property access - vvfat: Fix reading files with non-continuous clusters - vvfat: Fix bug in writing to middle of file - savevm: Fix load_snapshot error path crash - hw/dma/xilinx_axidma: Use semicolon at end of statement, not comma - hw/remote/message.c: Don't directly invoke DeviceClass:reset - crypto/tlscredspsk: Free username on finalize - hw/display/vhost-user-gpu.c: fix vhost_user_gpu_chr_read() - virtio: remove virtio_tswap16s() call in vring_packed_event_read() - char-stdio: Restore blocking mode of stdout on exit - hw/ppc: spapr: Use qemu_vfree() to free spapr->htab - smbios: sanitize type from external type before checking have_fields_bitmap - spapr_pci: fix leak in spapr_phb_vfio_get_loc_code - KVM: use store-release to mark dirty pages as harvested - monitor/hmp: print trace as option in help for log command - tpm_crb: Avoid backend startup just before shutdown under Xen - crypto/block-luks: make range overlap check more readable - spapr: Free stdout path - target/rx: Use target_ulong for address in LI - virtio-pci: Fix the use of an uninitialized irqfd - rtl8139: Fix behaviour for old kernels. - virtio-rng: block max-bytes=0 MIME-Version: 1.0 - hw/audio/es1370: Clean up comment - vhost-user-server: do not set memory fd non-blocking - ui: reject extended clipboard message if not activated - virtio-net: Fix vhost virtqueue notifiers for RSS - hw/misc/applesmc: Fix memory leak in reset() handler Signed-off-by: Jiabo Feng <fengjiabo1@huawei.com> (cherry picked from commit db7a5d9a7239db307c8c1454fab5f8a92fd486b8)
51 lines
1.9 KiB
Diff
51 lines
1.9 KiB
Diff
From 9399660f4ef94129f4f8ba9277a316bd6e7151b5 Mon Sep 17 00:00:00 2001
|
|
From: Amjad Alsharafi <amjadsharafi10@gmail.com>
|
|
Date: Sat, 20 Jul 2024 18:13:33 +0800
|
|
Subject: [PATCH] vvfat: Fix reading files with non-continuous clusters
|
|
|
|
When reading with `read_cluster` we get the `mapping` with
|
|
`find_mapping_for_cluster` and then we call `open_file` for this
|
|
mapping.
|
|
The issue appear when its the same file, but a second cluster that is
|
|
not immediately after it, imagine clusters `500 -> 503`, this will give
|
|
us 2 mappings one has the range `500..501` and another `503..504`, both
|
|
point to the same file, but different offsets.
|
|
|
|
When we don't open the file since the path is the same, we won't assign
|
|
`s->current_mapping` and thus accessing way out of bound of the file.
|
|
|
|
From our example above, after `open_file` (that didn't open anything) we
|
|
will get the offset into the file with
|
|
`s->cluster_size*(cluster_num-s->current_mapping->begin)`, which will
|
|
give us `0x2000 * (504-500)`, which is out of bound for this mapping and
|
|
will produce some issues.
|
|
|
|
Signed-off-by: Amjad Alsharafi <amjadsharafi10@gmail.com>
|
|
Message-ID: <1f3ea115779abab62ba32c788073cdc99f9ad5dd.1721470238.git.amjadsharafi10@gmail.com>
|
|
[kwolf: Simplified the patch based on Amjad's analysis and input]
|
|
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
|
|
(cherry picked from commit 5eed3db336506b529b927ba221fe0d836e5b8819)
|
|
Signed-off-by: zhujun2 <zhujun2_yewu@cmss.chinamobile.com>
|
|
---
|
|
block/vvfat.c | 3 ++-
|
|
1 file changed, 2 insertions(+), 1 deletion(-)
|
|
|
|
diff --git a/block/vvfat.c b/block/vvfat.c
|
|
index 5dacc6cfac..9af817088f 100644
|
|
--- a/block/vvfat.c
|
|
+++ b/block/vvfat.c
|
|
@@ -1368,8 +1368,9 @@ static int open_file(BDRVVVFATState* s,mapping_t* mapping)
|
|
return -1;
|
|
vvfat_close_current_file(s);
|
|
s->current_fd = fd;
|
|
- s->current_mapping = mapping;
|
|
}
|
|
+
|
|
+ s->current_mapping = mapping;
|
|
return 0;
|
|
}
|
|
|
|
--
|
|
2.41.0.windows.1
|
|
|