Re: [PATCH-for-5.2 v2] hw/intc: fix heap-buffer-overflow in rxicu_realize()

2020-11-20 Thread Philippe Mathieu-Daudé
Hi Peter, On 11/20/20 5:41 PM, Peter Maydell wrote: > On Fri, 20 Nov 2020 at 13:44, Peter Maydell wrote: >> >> On Wed, 11 Nov 2020 at 14:18, Chen Qun wrote: >>> >>> When 'j = icu->nr_sense – 1', the 'j < icu->nr_sense' condition is true, >>> then 'j = icu->nr_sense', the'icu->init_sense[j]' has

Re: [PATCH-for-5.2 v2] hw/intc: fix heap-buffer-overflow in rxicu_realize()

2020-11-20 Thread Peter Maydell
On Fri, 20 Nov 2020 at 13:44, Peter Maydell wrote: > > On Wed, 11 Nov 2020 at 14:18, Chen Qun wrote: > > > > When 'j = icu->nr_sense – 1', the 'j < icu->nr_sense' condition is true, > > then 'j = icu->nr_sense', the'icu->init_sense[j]' has out-of-bounds access. > > Suggested-by: Peter Maydell >

Re: [PATCH-for-5.2 v2] hw/intc: fix heap-buffer-overflow in rxicu_realize()

2020-11-20 Thread Peter Maydell
On Wed, 11 Nov 2020 at 14:18, Chen Qun wrote: > > When 'j = icu->nr_sense – 1', the 'j < icu->nr_sense' condition is true, > then 'j = icu->nr_sense', the'icu->init_sense[j]' has out-of-bounds access. > > The asan showed stack: > ERROR: AddressSanitizer: heap-buffer-overflow on address 0x60404

RE: [PATCH-for-5.2 v2] hw/intc: fix heap-buffer-overflow in rxicu_realize()

2020-11-15 Thread Chenqun (kuhn)
Kindly ping! Maybe it should be need for version 5.2. > -Original Message- > From: Chenqun (kuhn) > Sent: Wednesday, November 11, 2020 10:18 PM > To: qemu-devel@nongnu.org; qemu-triv...@nongnu.org > Cc: Zhanghailiang ; ganqixin > ; f4...@amsat.org; Chenqun (kuhn) > ; Peter Maydell ; > Eul