diff mbox series

[v1] hw/smbios: verify header type for file before using it

Message ID 20211129135211.1114466-1-d-tatianin@yandex-team.ru
State New
Headers show
Series [v1] hw/smbios: verify header type for file before using it | expand

Commit Message

Daniil Tatianin Nov. 29, 2021, 1:52 p.m. UTC
Signed-off-by: Daniil Tatianin <d-tatianin@yandex-team.ru>
---
 hw/smbios/smbios.c | 6 ++++++
 1 file changed, 6 insertions(+)

Comments

Igor Mammedov Jan. 4, 2022, 9:34 a.m. UTC | #1
On Mon, 29 Nov 2021 16:52:11 +0300
Daniil Tatianin <d-tatianin@yandex-team.ru> wrote:

here should be more verbose description of the issue
preferably with a way to reproduce it.
and what/why patch does what it does.

> Signed-off-by: Daniil Tatianin <d-tatianin@yandex-team.ru>
> ---
>  hw/smbios/smbios.c | 6 ++++++
>  1 file changed, 6 insertions(+)
> 
> diff --git a/hw/smbios/smbios.c b/hw/smbios/smbios.c
> index 7397e56737..c55f77368a 100644
> --- a/hw/smbios/smbios.c
> +++ b/hw/smbios/smbios.c
> @@ -1163,6 +1163,12 @@ void smbios_entry_add(QemuOpts *opts, Error **errp)
>              return;
>          }
>  
> +        if (header->type > SMBIOS_MAX_TYPE) {
> +            error_setg(errp,
> +                       "invalid header type %d!", header->type);

3.0 spec says that types over 127 are valid and for use by OEM/etc,
but QEMU doesn't support anything over 127 due to limited size of
have_fields_bitmap.
So I'd rephrase it as "unsupported header type"

> +            return;
> +        }
> +
>          if (test_bit(header->type, have_fields_bitmap)) {
>              error_setg(errp,
>                         "can't load type %d struct, fields already specified!",
diff mbox series

Patch

diff --git a/hw/smbios/smbios.c b/hw/smbios/smbios.c
index 7397e56737..c55f77368a 100644
--- a/hw/smbios/smbios.c
+++ b/hw/smbios/smbios.c
@@ -1163,6 +1163,12 @@  void smbios_entry_add(QemuOpts *opts, Error **errp)
             return;
         }
 
+        if (header->type > SMBIOS_MAX_TYPE) {
+            error_setg(errp,
+                       "invalid header type %d!", header->type);
+            return;
+        }
+
         if (test_bit(header->type, have_fields_bitmap)) {
             error_setg(errp,
                        "can't load type %d struct, fields already specified!",