malloc 0xff0000030 bytes with vmxnet3
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
QEMU |
New
|
Undecided
|
Unassigned |
Bug Description
Hello,
This reproducer causes vmxnet3 to malloc 0xff0000030 bytes
cat << EOF | ./i386-
-device vmxnet3 -m 64 -nodefaults -qtest stdio -nographic
outl 0xcf8 0x80001014
outl 0xcfc 0xe0001000
outl 0xcf8 0x80001018
outl 0xcf8 0x80001004
outw 0xcfc 0x7
write 0x0 0x1 0xe1
write 0x1 0x1 0xfe
write 0x2 0x1 0xbe
write 0x3 0x1 0xba
write 0x3e 0x1 0x05
write 0x28 0x1 0xe1
write 0x29 0x1 0xfe
write 0x2a 0x1 0xff
write 0x2b 0x1 0xff
write 0x2c 0x1 0xff
write 0x2d 0x1 0xff
write 0x2e 0x1 0xff
write 0x2f 0x1 0xff
write 0x31c 0x1 0xff
writeq 0xe0001020 0xef0bff5ecafe0000
EOF
=======
==25727==ERROR: AddressSanitizer: allocator is out of memory trying to allocate 0xff0000030 bytes
#0 0x56476a43731d in malloc (/home/
#1 0x7fca345a8500 in g_malloc (/usr/lib/
#2 0x56476c616312 in vmxnet3_
#3 0x56476c6101ba in vmxnet3_
#4 0x56476c60d30f in vmxnet3_
#5 0x56476b11d383 in memory_
#6 0x56476b11c827 in access_
#7 0x56476b11a446 in memory_
#8 0x56476a4cb696 in flatview_
#9 0x56476a4b3eb6 in flatview_write /home/alxndr/
#10 0x56476a4b39d7 in address_space_write /home/alxndr/
#11 0x56476b1c4614 in qtest_process_
#12 0x56476b1bbc18 in qtest_process_inbuf /home/alxndr/
#13 0x56476b1ba8a5 in qtest_read /home/alxndr/
#14 0x56476e063f03 in qemu_chr_
#15 0x56476e064087 in qemu_chr_be_write /home/alxndr/
#16 0x56476e078373 in fd_chr_read /home/alxndr/
#17 0x56476e1cc734 in qio_channel_
#18 0x7fca345a2897 in g_main_
-Alex
Chronogically speaking #1913873 is a duplicate of #1890152...