qemu-e2k/hw/misc
Stefan Hajnoczi 363ba1c72f ivshmem: validate incoming_posn value from server
Check incoming_posn to avoid out-of-bounds array accesses if the ivshmem
server on the host sends invalid values.

Cc: Cam Macdonell <cam@cs.ualberta.ca>
Reported-by: Sebastian Krahmer <krahmer@suse.de>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
[AF: Tighten upper bound check for posn in close_guest_eventfds()]
Cc: qemu-stable@nongnu.org
Signed-off-by: Andreas Färber <afaerber@suse.de>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
2014-10-31 17:01:59 +01:00
..
macio PPC: Cuda: Use cuda timer to expose tbfreq to guest 2014-09-08 12:50:52 +02:00
a9scu.c
applesmc.c
arm11scu.c
arm_integrator_debug.c
arm_l2x0.c
arm_sysctl.c
cbus.c hw: Fix qemu_allocate_irqs() leaks 2014-06-30 21:13:30 +02:00
debugexit.c
eccmemctl.c
exynos4210_pmu.c
imx_ccm.c hw/misc/imx_ccm.c: Add missing VMState list terminator 2014-07-22 17:53:36 +01:00
ivshmem.c ivshmem: validate incoming_posn value from server 2014-10-31 17:01:59 +01:00
Makefile.objs
max111x.c
milkymist-hpdmc.c
milkymist-pfpu.c
mst_fpga.c
omap_clk.c
omap_gpmc.c omap_gpmc.c: Remove duplicate assignment 2014-10-24 12:19:12 +01:00
omap_l4.c
omap_sdrc.c
omap_tap.c
pc-testdev.c
pci-testdev.c memory: remove memory_region_destroy 2014-08-18 12:06:21 +02:00
puv3_pm.c
pvpanic.c
sga.c
slavio_misc.c
tmp105.c
tmp105.h
vfio.c Add skip_dump flag to ignore memory region during dump 2014-10-31 11:29:01 +01:00
vmport.c
zynq_slcr.c