From 0e9bdb960045f98d70f765bbb585f1647e5fea08 Mon Sep 17 00:00:00 2001 From: Thomas Huth Date: Tue, 18 May 2021 13:51:23 -0400 Subject: [PATCH 3/5] pc-bios/s390-ccw: fix off-by-one error MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit RH-Author: Thomas Huth Message-id: <20210518135125.191329-2-thuth@redhat.com> Patchwork-id: 101548 O-Subject: [RHEL-8.5.0 qemu-kvm PATCH 1/3] pc-bios/s390-ccw: fix off-by-one error Bugzilla: 1942880 RH-Acked-by: Philippe Mathieu-Daudé RH-Acked-by: David Hildenbrand RH-Acked-by: Cornelia Huck This error takes effect when the magic value "zIPL" is located at the end of a block. For example if s2_cur_blk = 0x7fe18000 and the magic value "zIPL" is located at 0x7fe18ffc - 0x7fe18fff. Fixes: ba831b25262a ("s390-ccw: read stage2 boot loader data to find menu") Reviewed-by: Collin Walling Signed-off-by: Marc Hartmayer Message-Id: <20200924085926.21709-2-mhartmay@linux.ibm.com> Reviewed-by: Thomas Huth [thuth: Use "<= ... - 4" instead of "< ... - 3"] Signed-off-by: Thomas Huth (cherry picked from commit 5f97ba0c74ccace0a4014460de9751ff3c6f454a) Signed-off-by: Thomas Huth Signed-off-by: Danilo C. L. de Paula --- pc-bios/s390-ccw/bootmap.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c index e91ea719ff..bb6e003270 100644 --- a/pc-bios/s390-ccw/bootmap.c +++ b/pc-bios/s390-ccw/bootmap.c @@ -163,7 +163,7 @@ static bool find_zipl_boot_menu_banner(int *offset) int i; /* Menu banner starts with "zIPL" */ - for (i = 0; i < virtio_get_block_size() - 4; i++) { + for (i = 0; i <= virtio_get_block_size() - 4; i++) { if (magic_match(s2_cur_blk + i, ZIPL_MAGIC_EBCDIC)) { *offset = i; return true; -- 2.27.0