ohci doesn't check the 'num-ports' property
Bug #1581308 reported by
Li Qiang
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
QEMU |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
command:
qemu-system-x86_64 -m 1024 -enable-kvm /root/centos6.img -enable-kvm -device pci-ohci,
The ohci doesn't check the 'num-ports' property and would case an out-of-bands write,crash the qemu process.
ohci->num_ports = num_ports;
if (masterbus) {
USBPort *ports[
for(i = 0; i < num_ports; i++) {
}
The version of qemu is 2.6.0 release from
http://
To post a comment you must log in.
I was able to reproduce the crash, and proposed now a fix on the qemu-devel mailing list (see https:/ /patchwork. ozlabs. org/patch/ 625092/ for details)