Could this cause OOB bug ?
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
QEMU |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
In function megasas_
```c
static int megasas_
{
...
cdb = cmd->frame-
target_id = cmd->frame-
lun_id = cmd->frame-
cdb_len = cmd->frame-
...
if (cdb_len > 16) {
return MFI_STAT_
}
}
```
Two variables, frame_cmd and cdb_len, can be controlled by guest os. So can mfi_frame_
description: | updated |
Changed in qemu: | |
status: | Fix Committed → Fix Released |
QEMU emulator version 5.0.50 (v5.0.0- 533-gdebe78ce14 -dirty)