Do not advance past the end of the MADT with a truncated entry, and stop
instead of looping forever when an entry has zero length.
---
 i386/i386at/acpi_parse_apic.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/i386/i386at/acpi_parse_apic.c b/i386/i386at/acpi_parse_apic.c
index 0180dfd1..85123015 100644
--- a/i386/i386at/acpi_parse_apic.c
+++ b/i386/i386at/acpi_parse_apic.c
@@ -475,13 +475,19 @@ acpi_apic_parse_table(struct acpi_apic *apic)
     /* Initialize number of cpus */
     numcpus = apic_get_numcpus();
 
-    /* Search in APIC entry. */
-    while ((vm_offset_t)apic_entry < end) {
+    while ((vm_offset_t)apic_entry + sizeof(struct acpi_apic_dhdr) <= end) {
         struct acpi_apic_lapic *lapic_entry;
         struct acpi_apic_ioapic *ioapic_entry;
         struct acpi_apic_irq_override *irq_override_entry;
 
         printf("APIC entry=0x%p end=0x%x\n", apic_entry, end);
+
+        if (apic_entry->length == 0) {
+            printf("APIC: zero-length MADT entry type %#x, stopping\n",
+                   apic_entry->type);
+            break;
+        }
+
         /* Check entry type. */
         switch(apic_entry->type) {
 

Reply via email to