]> www.infradead.org Git - qemu-nvme.git/commit
hw/nvme: fix buffer overrun in nvme_changed_nslist (CVE-2021-3947) nvme-fixes-for-6.2 nvme-fixes-for-6.2-pull-request
authorKlaus Jensen <k.jensen@samsung.com>
Wed, 17 Nov 2021 13:12:56 +0000 (14:12 +0100)
committerKlaus Jensen <k.jensen@samsung.com>
Fri, 19 Nov 2021 06:32:19 +0000 (07:32 +0100)
commite2c57529c9306e4c9aac75d9879f6e7699584a22
treea75fc4514e0e425b406a96c544c8517ae04064f8
parent916b0f0b5264759c581badfdc0e1c5f98362dbda
hw/nvme: fix buffer overrun in nvme_changed_nslist (CVE-2021-3947)

Fix missing offset verification.

Cc: qemu-stable@nongnu.org
Cc: Philippe Mathieu-Daudé <philmd@redhat.com>
Reported-by: Qiuhao Li <Qiuhao.Li@outlook.com>
Fixes: f432fdfa121 ("support changed namespace asynchronous event")
Reviewed-by: Philippe Mathieu-Daudé <philmd@redhat.com>
Signed-off-by: Klaus Jensen <k.jensen@samsung.com>
hw/nvme/ctrl.c