diff mbox

[PULL,13/22] block: Detect multiplication overflow in bdrv_getlength

Message ID 1432308400-13958-14-git-send-email-kwolf@redhat.com
State New
Headers show

Commit Message

Kevin Wolf May 22, 2015, 3:26 p.m. UTC
From: Fam Zheng <famz@redhat.com>

Bogus image may have a large total_sectors that will overflow the
multiplication. For cleanness, fix the return code so the error message
will be meaningful.

Reported-by: Richard W.M. Jones <rjones@redhat.com>
Signed-off-by: Fam Zheng <famz@redhat.com>
Reviewed-by: Alberto Garcia <berto@igalia.com>
Reviewed-by: Markus Armbruster <armbru@redhat.com>
Signed-off-by: Kevin Wolf <kwolf@redhat.com>
---
 block.c | 1 +
 1 file changed, 1 insertion(+)
diff mbox

Patch

diff --git a/block.c b/block.c
index 325f727..f42d70e 100644
--- a/block.c
+++ b/block.c
@@ -2341,6 +2341,7 @@  int64_t bdrv_getlength(BlockDriverState *bs)
 {
     int64_t ret = bdrv_nb_sectors(bs);
 
+    ret = ret > INT64_MAX / BDRV_SECTOR_SIZE ? -EFBIG : ret;
     return ret < 0 ? ret : ret * BDRV_SECTOR_SIZE;
 }