|
|
9ae3a8 |
From c5e26182fedef98b73f50e9fac3ae09696e59880 Mon Sep 17 00:00:00 2001
|
|
|
9ae3a8 |
From: Gerd Hoffmann <kraxel@redhat.com>
|
|
|
9ae3a8 |
Date: Wed, 26 Feb 2014 11:44:47 +0100
|
|
|
9ae3a8 |
Subject: [PATCH 2/6] qxl: add sanity check
|
|
|
9ae3a8 |
|
|
|
9ae3a8 |
RH-Author: Gerd Hoffmann <kraxel@redhat.com>
|
|
|
9ae3a8 |
Message-id: <1393415087-3776-2-git-send-email-kraxel@redhat.com>
|
|
|
9ae3a8 |
Patchwork-id: 57815
|
|
|
9ae3a8 |
O-Subject: [RHEL-7 qemu-kvm PATCH 1/1] qxl: add sanity check
|
|
|
9ae3a8 |
Bugzilla: 751937
|
|
|
9ae3a8 |
RH-Acked-by: Laszlo Ersek <lersek@redhat.com>
|
|
|
9ae3a8 |
RH-Acked-by: Dr. David Alan Gilbert (git) <dgilbert@redhat.com>
|
|
|
9ae3a8 |
RH-Acked-by: Paolo Bonzini <pbonzini@redhat.com>
|
|
|
9ae3a8 |
|
|
|
9ae3a8 |
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
|
|
|
9ae3a8 |
Reviewed-by: Laszlo Ersek <lersek@redhat.com>
|
|
|
9ae3a8 |
(cherry picked from commit 9c70434f825fd0d2e89d1aa0f872159378d0aab3)
|
|
|
9ae3a8 |
---
|
|
|
9ae3a8 |
hw/display/qxl.c | 8 +++++++-
|
|
|
9ae3a8 |
1 file changed, 7 insertions(+), 1 deletion(-)
|
|
|
9ae3a8 |
|
|
|
9ae3a8 |
Signed-off-by: Miroslav Rezanina <mrezanin@redhat.com>
|
|
|
9ae3a8 |
---
|
|
|
9ae3a8 |
hw/display/qxl.c | 8 +++++++-
|
|
|
9ae3a8 |
1 files changed, 7 insertions(+), 1 deletions(-)
|
|
|
9ae3a8 |
|
|
|
9ae3a8 |
diff --git a/hw/display/qxl.c b/hw/display/qxl.c
|
|
|
9ae3a8 |
index 4381d97..4fe4f1b 100644
|
|
|
9ae3a8 |
--- a/hw/display/qxl.c
|
|
|
9ae3a8 |
+++ b/hw/display/qxl.c
|
|
|
9ae3a8 |
@@ -1417,7 +1417,7 @@ static int qxl_destroy_primary(PCIQXLDevice *d, qxl_async_io async)
|
|
|
9ae3a8 |
return 1;
|
|
|
9ae3a8 |
}
|
|
|
9ae3a8 |
|
|
|
9ae3a8 |
-static void qxl_set_mode(PCIQXLDevice *d, int modenr, int loadvm)
|
|
|
9ae3a8 |
+static void qxl_set_mode(PCIQXLDevice *d, unsigned int modenr, int loadvm)
|
|
|
9ae3a8 |
{
|
|
|
9ae3a8 |
pcibus_t start = d->pci.io_regions[QXL_RAM_RANGE_INDEX].addr;
|
|
|
9ae3a8 |
pcibus_t end = d->pci.io_regions[QXL_RAM_RANGE_INDEX].size + start;
|
|
|
9ae3a8 |
@@ -1427,6 +1427,12 @@ static void qxl_set_mode(PCIQXLDevice *d, int modenr, int loadvm)
|
|
|
9ae3a8 |
.mem_start = start,
|
|
|
9ae3a8 |
.mem_end = end
|
|
|
9ae3a8 |
};
|
|
|
9ae3a8 |
+
|
|
|
9ae3a8 |
+ if (modenr >= d->modes->n_modes) {
|
|
|
9ae3a8 |
+ qxl_set_guest_bug(d, "mode number out of range");
|
|
|
9ae3a8 |
+ return;
|
|
|
9ae3a8 |
+ }
|
|
|
9ae3a8 |
+
|
|
|
9ae3a8 |
QXLSurfaceCreate surface = {
|
|
|
9ae3a8 |
.width = mode->x_res,
|
|
|
9ae3a8 |
.height = mode->y_res,
|
|
|
9ae3a8 |
--
|
|
|
9ae3a8 |
1.7.1
|
|
|
9ae3a8 |
|