qemu-e2k/hw
Michael S. Tsirkin a9c380db3b ssi-sd: fix buffer overrun on invalid state load
CVE-2013-4537

s->arglen is taken from wire and used as idx
in ssi_sd_transfer().

Validate it before access.

Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Juan Quintela <quintela@redhat.com>
2014-05-05 22:15:03 +02:00
..
9pfs
acpi
alpha
arm pxa2xx: avoid buffer overrun on incoming migration 2014-05-05 22:15:02 +02:00
audio
block
bt
char
core
cpu
cris
display ssd0323: fix buffer overun on invalid state load 2014-05-05 22:15:02 +02:00
dma
gpio zaurus: fix buffer overrun on invalid state load 2014-05-05 22:15:02 +02:00
i2c
i386
ide ahci: fix buffer overrun on invalid state load 2014-05-05 22:15:02 +02:00
input tsc210x: fix buffer overrun on invalid state load 2014-05-05 22:15:02 +02:00
intc
ipack
isa
lm32
m68k
microblaze
mips
misc
moxie
net
nvram
openrisc
pci vmstate: s/VMSTATE_INT32_LE/VMSTATE_INT32_POSITIVE_LE/ 2014-05-05 22:15:03 +02:00
pci-bridge
pci-host
pcmcia
ppc
s390x
scsi virtio-scsi: fix buffer overrun on invalid state load 2014-05-05 22:15:02 +02:00
sd ssi-sd: fix buffer overrun on invalid state load 2014-05-05 22:15:03 +02:00
sh4
sparc
sparc64
ssi pl022: fix buffer overun on invalid state load 2014-05-05 22:15:02 +02:00
timer hpet: fix buffer overrun on invalid state load 2014-05-05 22:15:02 +02:00
tpm
unicore32
usb usb: sanity check setup_index+setup_len in post_load 2014-05-05 22:15:03 +02:00
virtio virtio: validate num_sg when mapping 2014-05-05 22:15:02 +02:00
watchdog
xen
xtensa
Makefile.objs