> -----Original Message-----
> From: [email protected]
> [mailto:[email protected]] On Behalf Of Peter Crosthwaite
> Sent: Tuesday, August 19, 2014 11:12 PM
> To: Gonglei (Arei)
> Cc: [email protected] Developers; Huangweidong (C); Michael S. Tsirkin
> Subject: Re: [Qemu-devel] [PATCH] pcihp: fix possible array out of bounds
> 
> On Tue, Aug 19, 2014 at 5:18 PM,  <[email protected]> wrote:
> > From: Gonglei <[email protected]>
> >
> > When 'bsel == ACPI_PCIHP_MAX_HOTPLUG_BUS', the
> > s->acpi_pcihp_pci_status[bsel] array will out of bounds.
> >
> > Add check for this.
> >
> > Signed-off-by: Gonglei <[email protected]>
> 
> Reviewed-by: Peter Crosthwaite <[email protected]>
> 
Thanks.

Best regards,
-Gonglei
> > ---
> >  hw/acpi/pcihp.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/hw/acpi/pcihp.c b/hw/acpi/pcihp.c
> > index fae663a..34dedf1 100644
> > --- a/hw/acpi/pcihp.c
> > +++ b/hw/acpi/pcihp.c
> > @@ -231,7 +231,7 @@ static uint64_t pci_read(void *opaque, hwaddr addr,
> unsigned int size)
> >      uint32_t val = 0;
> >      int bsel = s->hotplug_select;
> >
> > -    if (bsel < 0 || bsel > ACPI_PCIHP_MAX_HOTPLUG_BUS) {
> > +    if (bsel < 0 || bsel >= ACPI_PCIHP_MAX_HOTPLUG_BUS) {
> >          return 0;
> >      }
> >
> > --
> > 1.7.12.4
> >
> >
> >

Reply via email to