Message ID | 20180628034652.24152-2-f4bug@amsat.org |
---|---|
State | New |
Headers | show
Return-Path: <qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org> X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (mailfrom) smtp.mailfrom=nongnu.org (client-ip=2001:4830:134:3::11; helo=lists.gnu.org; envelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org; receiver=<UNKNOWN>) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=amsat.org Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.b="nxZ8I3h1"; dkim-atps=neutral Received: from lists.gnu.org (lists.gnu.org [IPv6:2001:4830:134:3::11]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 41GQjG6xB8z9s31 for <incoming@patchwork.ozlabs.org>; Thu, 28 Jun 2018 13:48:02 +1000 (AEST) Received: from localhost ([::1]:34392 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from <qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>) id 1fYNua-0007xF-KH for incoming@patchwork.ozlabs.org; Wed, 27 Jun 2018 23:48:00 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:46063) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from <philippe.mathieu.daude@gmail.com>) id 1fYNto-0007uB-Qo for qemu-devel@nongnu.org; Wed, 27 Jun 2018 23:47:18 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from <philippe.mathieu.daude@gmail.com>) id 1fYNth-0000Us-50 for qemu-devel@nongnu.org; Wed, 27 Jun 2018 23:47:12 -0400 Received: from mail-qk0-x236.google.com ([2607:f8b0:400d:c09::236]:45192) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from <philippe.mathieu.daude@gmail.com>) id 1fYNth-0000UH-0E for qemu-devel@nongnu.org; Wed, 27 Jun 2018 23:47:05 -0400 Received: by mail-qk0-x236.google.com with SMTP id c198-v6so2255483qkg.12 for <qemu-devel@nongnu.org>; Wed, 27 Jun 2018 20:47:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=G2ahE2OAFPa8WL+ImNAi6EA+Wl0IRSrivFrhWJ7juV0=; b=nxZ8I3h1CoBVFe0q3kh7xlF00++SsJVxvhDpL7GDn0W2ZEumIKcG/75qG0KLiCcmXS gWvrWkNAjLpl1DH90vRmJsefjq+APPwwEMYfnEx5YF7JlGs0/9w3WPYDx16rRsfPnDcQ eHUuBaaaqNGJxC+rn6OokVHHfNblAi5nirNXWoL1bYsnQZwaEoiKiLB7IpoM14lY4bAt d4QHHpVQO+Pq+ScvuHwe/7n1RZj0xuUW/quuhAqnzIireY/JvCAdJ58fZVkWWRRh2l9D KPQLQbjhXO1GSCaaeOXv+FgNJ4yeRapq+vMS5ug8HNJBBMF2SoRSD0vmyAbA7xfUq5K2 AlcA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=G2ahE2OAFPa8WL+ImNAi6EA+Wl0IRSrivFrhWJ7juV0=; b=Z0Qe9eAI+Dds2vuHmZK9EhKVx+DwGmP8lZkj2lCTcZ1anEDYFf0NhkeJ4xgz+ZPDwf Lre0t0CjsaNxu17+2/1AZiTSl00tzka7aODAxL0SaePHSnwpDfqg0qaWSsh4LKS7oGfL wOo+Lrw1GXqQB7c00HeXyKeSPx5lB9HPDVwWJNLB0HpwJ+u95a7hfmMbzACZdOCxBvwh uNt8bQEE36XM7zseB1c/2Yr4PAYh6ixnVFTZ/nDK/HgtWho/0lvi/WLKlgKvuA2x0EQv pBNRnyIctD2I3+yJQeIAH3xFB3kCiPhXjuHlDSpyH/WmqyuTXEMbBwhEWKcK71drmFOx +IOA== X-Gm-Message-State: APt69E1IfL5oPaCuOI0OLU30KHgCUDP/JrothhB7x3QWuc0tc4mloCud ePCn3gaSCfsuB9UzlLPnnCSMnI2F X-Google-Smtp-Source: AAOMgpfms8o+hX7CI36vsgQ8zOXXDRUsPRJnj7gjGEg2bNLZJVWgzp/gtdFhTgPE1e1wGuzYtArsNA== X-Received: by 2002:a37:8ac3:: with SMTP id m186-v6mr7709444qkd.6.1530157624443; Wed, 27 Jun 2018 20:47:04 -0700 (PDT) Received: from x1.local ([138.117.48.222]) by smtp.gmail.com with ESMTPSA id e11-v6sm4125854qkb.4.2018.06.27.20.47.01 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 27 Jun 2018 20:47:03 -0700 (PDT) From: =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= <f4bug@amsat.org> To: Laurent Vivier <laurent@vivier.eu> Date: Thu, 28 Jun 2018 00:46:41 -0300 Message-Id: <20180628034652.24152-2-f4bug@amsat.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180628034652.24152-1-f4bug@amsat.org> References: <20180628034652.24152-1-f4bug@amsat.org> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2607:f8b0:400d:c09::236 Subject: [Qemu-devel] [PATCH v2 01/12] linux-user/syscall: Verify recvfrom(addr) is user-writable X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: <qemu-devel.nongnu.org> List-Unsubscribe: <https://lists.nongnu.org/mailman/options/qemu-devel>, <mailto:qemu-devel-request@nongnu.org?subject=unsubscribe> List-Archive: <http://lists.nongnu.org/archive/html/qemu-devel/> List-Post: <mailto:qemu-devel@nongnu.org> List-Help: <mailto:qemu-devel-request@nongnu.org?subject=help> List-Subscribe: <https://lists.nongnu.org/mailman/listinfo/qemu-devel>, <mailto:qemu-devel-request@nongnu.org?subject=subscribe> Cc: =?utf-8?q?Guido_G=C3=BCnther?= <agx@sigxcpu.org>, Riku Voipio <riku.voipio@iki.fi>, =?utf-8?q?Philippe_Mathieu-Daud?= =?utf-8?b?w6k=?= <f4bug@amsat.org>, qemu-devel@nongnu.org Errors-To: qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org Sender: "Qemu-devel" <qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org> |
Series |
linux-user: strace improvements
|
expand
|
diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 2117fb13b4..ad40682cee 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -4154,6 +4154,11 @@ static abi_long do_recvfrom(int fd, abi_ulong msg, size_t len, int flags, ret = -TARGET_EINVAL; goto fail; } + if (!access_ok(VERIFY_WRITE, target_addr, addrlen)) { + ret = -TARGET_EFAULT; + goto fail; + } + addr = alloca(addrlen); ret = get_errno(safe_recvfrom(fd, host_msg, len, flags, addr, &addrlen));