s390x/sclpcpi: check event length field before reading from buffer
A guest might send a too short SCCB with SCLP_EVENT_CTRL_PGM_ID. QEMU
would fill its data structures with garbage data. Check for the precise
length of the CBI data structure and reject otherwise.
Fixes: f345978f24 ("hw/s390x: add Control-Program Identification to QOM")
Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Janosch Frank <frankja@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Message-ID: <20260709142906.197474-3-borntraeger@linux.ibm.com>
Signed-off-by: Cornelia Huck <cohuck@redhat.com>
This commit is contained in:
committed by
Cornelia Huck
parent
20701190e0
commit
8a116a2853
@@ -97,6 +97,11 @@ static int write_event_data(SCLPEvent *event, EventBufferHeader *evt_buf_hdr)
|
||||
ebh);
|
||||
SCLPEventCPI *e = SCLP_EVENT_CPI(event);
|
||||
|
||||
/* Caller checks sccb length, buffer header checking is our duty */
|
||||
if (be16_to_cpu(evt_buf_hdr->length) != sizeof(ControlProgramIdMsg)) {
|
||||
return SCLP_RC_INCONSISTENT_LENGTHS;
|
||||
}
|
||||
|
||||
ascii_put(e->system_type, (char *)cpim->data.system_type,
|
||||
sizeof(cpim->data.system_type));
|
||||
ascii_put(e->system_name, (char *)cpim->data.system_name,
|
||||
|
||||
Reference in New Issue
Block a user