qubes-linux-kernel/0011-xen-netfront-add-range-check-for-Tx-response-id.patch

36 lines
1.1 KiB
Diff
Raw Normal View History

2019-05-11 09:23:56 +00:00
From d81bcfcdadd17347a661d1379960d3144d2f69fa Mon Sep 17 00:00:00 2001
2015-12-17 08:24:01 +00:00
From: =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?=
<marmarek@invisiblethingslab.com>
Date: Wed, 16 Dec 2015 05:22:24 +0100
2018-08-15 12:57:19 +00:00
Subject: [PATCH] xen-netfront: add range check for Tx response id
2015-12-17 08:24:01 +00:00
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Tx response ID is fetched from shared page, so make sure it is sane
before using it as an array index.
This is part of XSA155.
CC: stable@vger.kernel.org
Signed-off-by: Marek Marczykowski-Górecki <marmarek@invisiblethingslab.com>
---
drivers/net/xen-netfront.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/xen-netfront.c b/drivers/net/xen-netfront.c
2019-03-15 21:28:57 +00:00
index 834a7950bea1..a429ab24114b 100644
2015-12-17 08:24:01 +00:00
--- a/drivers/net/xen-netfront.c
+++ b/drivers/net/xen-netfront.c
2019-03-15 21:28:57 +00:00
@@ -392,6 +392,7 @@ static void xennet_tx_buf_gc(struct netfront_queue *queue)
2015-12-17 08:24:01 +00:00
continue;
id = txrsp.id;
+ BUG_ON(id >= NET_TX_RING_SIZE);
skb = queue->tx_skbs[id].skb;
if (unlikely(gnttab_query_foreign_access(
queue->grant_tx_ref[id]) != 0)) {
--
2019-03-15 21:28:57 +00:00
2.20.1
2015-12-17 08:24:01 +00:00