Paolo,
Sorry but the previous patch was bad.
Use this patch instead it uses the correct check of
if (r->req.cmd.lba > r->req.cmd.lba + len
|| r->req.cmd.lba + len > s->qdev.max_lba + 1) {- [Qemu-devel] [PATCH] SCSI improved LBA-out-of-range checks... Ronnie Sahlberg
- [Qemu-devel] [PATCH] SCSI Improved checking for LBA ... Ronnie Sahlberg
