]> www.infradead.org Git - users/dwmw2/qemu.git/commitdiff
virtio-gpu: fix information leak in getting capset info dispatch
authorLi Qiang <liqiang6-s@360.cn>
Tue, 1 Nov 2016 09:53:11 +0000 (02:53 -0700)
committerGerd Hoffmann <kraxel@redhat.com>
Mon, 5 Dec 2016 08:37:52 +0000 (09:37 +0100)
In virgl_cmd_get_capset_info dispatch function, the 'resp' hasn't
been full initialized before writing to the guest. This will leak
the 'resp.padding' and 'resp.hdr.padding' fieds to the guest. This
patch fix this issue.

Signed-off-by: Li Qiang <liqiang6-s@360.cn>
Message-id: 5818661e.0860240a.77264.7a56@mx.google.com
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
hw/display/virtio-gpu-3d.c

index 758d33a09d9dc995b9d28850bdb33bb3870f9f8d..23f39de94d3a4e355673f14cbced5aed7e312e87 100644 (file)
@@ -347,6 +347,7 @@ static void virgl_cmd_get_capset_info(VirtIOGPU *g,
 
     VIRTIO_GPU_FILL_CMD(info);
 
+    memset(&resp, 0, sizeof(resp));
     if (info.capset_index == 0) {
         resp.capset_id = VIRTIO_GPU_CAPSET_VIRGL;
         virgl_renderer_get_cap_set(resp.capset_id,