hw/display/artist: Check offset in draw_line to avoid buffer over-run
Invalid I/O writes can craft an offset out of the vram_buffer range. We avoid: Program terminated with signal SIGSEGV, Segmentation fault. 284 *dst &= ~plane_mask; (gdb) bt #0 0x000055d5dccdc5c0 in artist_rop8 (s=0x55d5defee510, dst=0x7f8e84ed8216 <error: Cannot access memory at address 0x7f8e84ed8216>, val=0 '\000') at hw/display/artist.c:284 #1 0x000055d5dccdcf83 in fill_window (s=0x55d5defee510, startx=22, starty=5674, width=65, height=5697) at hw/display/artist.c:551 #2 0x000055d5dccddfb9 in artist_reg_write (opaque=0x55d5defee510, addr=1051140, val=4265537, size=4) at hw/display/artist.c:902 #3 0x000055d5dcb42a7c in memory_region_write_accessor (mr=0x55d5defeea10, addr=1051140, value=0x7ffe57db08c8, size=4, shift=0, mask=4294967295, attrs=...) at memory.c:483 Reported-by: LLVM libFuzzer Signed-off-by: Philippe Mathieu-Daudé <f4bug@amsat.org> Signed-off-by: Helge Deller <deller@gmx.de>
This commit is contained in:
parent
b899fe41ce
commit
b87a7355de
@ -555,7 +555,7 @@ static void fill_window(ARTISTState *s, int startx, int starty,
|
||||
static void draw_line(ARTISTState *s, int x1, int y1, int x2, int y2,
|
||||
bool update_start, int skip_pix, int max_pix)
|
||||
{
|
||||
struct vram_buffer *buf;
|
||||
struct vram_buffer *buf = &s->vram_buffer[ARTIST_BUFFER_AP];
|
||||
uint8_t color;
|
||||
int dx, dy, t, e, x, y, incy, diago, horiz;
|
||||
bool c1;
|
||||
@ -563,6 +563,12 @@ static void draw_line(ARTISTState *s, int x1, int y1, int x2, int y2,
|
||||
|
||||
trace_artist_draw_line(x1, y1, x2, y2);
|
||||
|
||||
if (x1 * y1 >= buf->size || x2 * y2 >= buf->size) {
|
||||
qemu_log_mask(LOG_GUEST_ERROR,
|
||||
"draw_line (%d,%d) (%d,%d)\n", x1, y1, x2, y2);
|
||||
return;
|
||||
}
|
||||
|
||||
if (update_start) {
|
||||
s->vram_start = (x2 << 16) | y2;
|
||||
}
|
||||
@ -620,7 +626,6 @@ static void draw_line(ARTISTState *s, int x1, int y1, int x2, int y2,
|
||||
x = x1;
|
||||
y = y1;
|
||||
color = artist_get_color(s);
|
||||
buf = &s->vram_buffer[ARTIST_BUFFER_AP];
|
||||
|
||||
do {
|
||||
if (c1) {
|
||||
|
Loading…
Reference in New Issue
Block a user