Signed-off-by: Philippe Mathieu-Daudé <[email protected]>
Tested-By: Guido Günther <[email protected]>
Reviewed-by: Laurent Vivier <[email protected]>
---
linux-user/syscall.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/linux-user/syscall.c b/linux-user/syscall.c
index 2117fb13b4..ad40682cee 100644
--- a/linux-user/syscall.c
+++ b/linux-user/syscall.c
@@ -4154,6 +4154,11 @@ static abi_long do_recvfrom(int fd, abi_ulong msg,
size_t len, int flags,
ret = -TARGET_EINVAL;
goto fail;
}
+ if (!access_ok(VERIFY_WRITE, target_addr, addrlen)) {
+ ret = -TARGET_EFAULT;
+ goto fail;
+ }
+
addr = alloca(addrlen);
ret = get_errno(safe_recvfrom(fd, host_msg, len, flags,
addr, &addrlen));
--
2.18.0