- Introduce the SM4 cipher algorithms (OSCCA GB/T 32907-2016).
- intel_iommu: Add missed sanity check for 256-bit invalidation queue
- linux-user: use 'max' instead of 'qemu32' / 'qemu64' by default
- chardev/baum: Use definitions to avoid dynamic stack allocation
- ui/console: Get tab completion working again in the SDL monitor vc
- s390x/tcg: Fix opcode for lzrf
- virtiofsd: use g_date_time_get_microsecond to get subsecond
- ui/curses: Avoid dynamic stack allocation
- target/m68k: always call gen_exit_tb() after writes to SR
- target/m68k: Perform writback before modifying SR
- target/m68k: Fix MACSR to CCR
- target/m68k: Implement atomic test-and-set
- block/nvme: nvme_process_completion() fix bound for cid
- hw/pci-host: pnv_phb{3, 4}: Fix heap out-of-bound access failure
- target/ppc: Zero second doubleword of VSR registers for FPR insns
- target/ppc: Set OV32 when OV is set
- target/ppc: Zero second doubleword for VSX madd instructions
- target/ppc: Set result to QNaN for DENBCD when VXCVI occurs
- hw/pci: Add parenthesis to PCI_BUILD_BDF macro
- intel_iommu: Send IQE event when setting reserved bit in IQT_TAIL
- acpi: cpuhp: fix guest-visible maximum access size to the legacy reg block
- acpi: ged: Add macro for acpi sleep control register
- hw/pci-bridge: Add a Kconfig switch for the normal PCI bridge
- ui/vnc: fix handling of VNC_FEATURE_XVP
- s390/sclp: fix SCLP facility map
- docs/tools/qemu-img.rst: fix typo (sumarizes)
- chardev/char: fix qemu_chr_is_busy() check
- edu: fix DMA range upper bound check
- platform-bus: fix refcount leak
- hw/net/virtio-net: fix qemu set used ring flag even vhost started
- hw/net/can/sja1000: fix bug for single acceptance filter and standard frame
- tests/avocado: fix typo in replay_linux
- util/userfaultfd: Remove unused uffd_poll_events
- hw/core/ptimer: fix timer zero period condition for freq > 1GHz
- hcd-ohci: Drop ohci_service_iso_td() if ed->head & OHCI_DPTR_MASK is zero
- tests/unit/test-vmstate: Avoid dynamic stack allocation
- hw/usb/hcd-ohci: Use definition to avoid dynamic stack allocation
- hw/i386/multiboot: Avoid dynamic stack allocation
- hw/ppc/spapr: Fix code style problems reported by checkpatch
- chardev/baum: Replace magic values by X_MAX / Y_MAX definitions
- hw/intc/xics: Avoid dynamic stack allocation
- hw/net/e1000e_core: Use definition to avoid dynamic stack allocation
- intel_iommu: Fix invalidation descriptor type field
- configs: Fix typo in the sh4-softmmu devices config file
Signed-off-by: Jiabo Feng <fengjiabo1@huawei.com>
(cherry picked from commit 9813ed21ec2499c50cb58ac5fb114a1641708eb2)
61 lines
2.5 KiB
Diff
61 lines
2.5 KiB
Diff
From 1a122b51bddc216fa129e039012711a1a1a8b6b4 Mon Sep 17 00:00:00 2001
|
|
From: Liu Jing <liujing_yewu@cmss.chinamobile.com>
|
|
Date: Mon, 14 Oct 2024 16:42:03 +0800
|
|
Subject: [PATCH] hw/pci-host: pnv_phb{3, 4}: Fix heap out-of-bound access
|
|
failure
|
|
MIME-Version: 1.0
|
|
Content-Type: text/plain; charset=UTF-8
|
|
Content-Transfer-Encoding: 8bit
|
|
|
|
pnv_phb3_root_bus_info and pnv_phb4_root_bus_info are missing the
|
|
instance_size initialization. This results in accessing out-of-bound
|
|
memory when setting 'chip-id' and 'phb-id', and eventually crashes
|
|
glib's malloc functionality with the following message:
|
|
|
|
"qemu-system-ppc64: GLib: ../glib-2.72.3/glib/gmem.c:131: failed to allocate 3232 bytes"
|
|
|
|
This issue was noticed only when running qtests with QEMU Windows
|
|
32-bit executable. Windows 64-bit, Linux 32/64-bit do not expose
|
|
this bug though.
|
|
|
|
Fixes: 9ae1329ee2fe ("ppc/pnv: Add models for POWER8 PHB3 PCIe Host bridge")
|
|
Fixes: 4f9924c4d4cf ("ppc/pnv: Add models for POWER9 PHB4 PCIe Host bridge")
|
|
Reviewed-by: Cédric Le Goater <clg@kaod.org>
|
|
Signed-off-by: Xuzhou Cheng <xuzhou.cheng@windriver.com>
|
|
Signed-off-by: Bin Meng <bin.meng@windriver.com>
|
|
Message-Id: <20220920103159.1865256-29-bmeng.cn@gmail.com>
|
|
Signed-off-by: Daniel Henrique Barboza <danielhb413@gmail.com>
|
|
Signed-off-by: Liu Jing <liujing_yewu@cmss.chinamobile.com>
|
|
---
|
|
hw/pci-host/pnv_phb3.c | 1 +
|
|
hw/pci-host/pnv_phb4.c | 1 +
|
|
2 files changed, 2 insertions(+)
|
|
|
|
diff --git a/hw/pci-host/pnv_phb3.c b/hw/pci-host/pnv_phb3.c
|
|
index 947efa77dc..bdc128013e 100644
|
|
--- a/hw/pci-host/pnv_phb3.c
|
|
+++ b/hw/pci-host/pnv_phb3.c
|
|
@@ -1130,6 +1130,7 @@ static void pnv_phb3_root_bus_class_init(ObjectClass *klass, void *data)
|
|
static const TypeInfo pnv_phb3_root_bus_info = {
|
|
.name = TYPE_PNV_PHB3_ROOT_BUS,
|
|
.parent = TYPE_PCIE_BUS,
|
|
+ .instance_size = sizeof(PnvPHB3RootBus),
|
|
.class_init = pnv_phb3_root_bus_class_init,
|
|
.interfaces = (InterfaceInfo[]) {
|
|
{ INTERFACE_PCIE_DEVICE },
|
|
diff --git a/hw/pci-host/pnv_phb4.c b/hw/pci-host/pnv_phb4.c
|
|
index 4e17a48d35..9f115da7ac 100644
|
|
--- a/hw/pci-host/pnv_phb4.c
|
|
+++ b/hw/pci-host/pnv_phb4.c
|
|
@@ -1321,6 +1321,7 @@ static void pnv_phb4_root_bus_class_init(ObjectClass *klass, void *data)
|
|
static const TypeInfo pnv_phb4_root_bus_info = {
|
|
.name = TYPE_PNV_PHB4_ROOT_BUS,
|
|
.parent = TYPE_PCIE_BUS,
|
|
+ .instance_size = sizeof(PnvPHB4RootBus),
|
|
.class_init = pnv_phb4_root_bus_class_init,
|
|
.interfaces = (InterfaceInfo[]) {
|
|
{ INTERFACE_PCIE_DEVICE },
|
|
--
|
|
2.41.0.windows.1
|
|
|