File CVE-2017-7718-qemuu-display-cirrus-OOB-read-access-issue.patch of Package xen.11319
Subject: fix :cirrus_vga fix OOB read case qemu Segmentation fault
From: hangaohuai hangaohuai@huawei.com Tue Mar 14 14:39:19 2017 +0800
Date: Thu Mar 16 08:58:15 2017 +0100:
Git: 215902d7b6fb50c6fc216fc74f770858278ed904
check the validity of parameters in cirrus_bitblt_rop_fwd_transp_xxx
and cirrus_bitblt_rop_fwd_xxx to avoid the OOB read which causes qemu Segmentation fault.
After the fix, we will touch the assert in
cirrus_invalidate_region:
assert(off_cur_end >= off_cur);
Signed-off-by: fangying <fangying1@huawei.com>
Signed-off-by: hangaohuai <hangaohuai@huawei.com>
Message-id: 20170314063919.16200-1-hangaohuai@huawei.com
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Index: xen-4.4.4-testing/tools/qemu-xen-dir-remote/hw/display/cirrus_vga_rop.h
===================================================================
--- xen-4.4.4-testing.orig/tools/qemu-xen-dir-remote/hw/display/cirrus_vga_rop.h
+++ xen-4.4.4-testing/tools/qemu-xen-dir-remote/hw/display/cirrus_vga_rop.h
@@ -98,6 +98,11 @@ glue(glue(cirrus_bitblt_rop_fwd_transp_,
uint8_t p;
dstpitch -= bltwidth;
srcpitch -= bltwidth;
+
+ if (bltheight > 1 && (dstpitch < 0 || srcpitch < 0)) {
+ return;
+ }
+
for (y = 0; y < bltheight; y++) {
for (x = 0; x < bltwidth; x++) {
p = *dst;
@@ -144,6 +149,11 @@ glue(glue(cirrus_bitblt_rop_fwd_transp_,
uint8_t p1, p2;
dstpitch -= bltwidth;
srcpitch -= bltwidth;
+
+ if (bltheight > 1 && (dstpitch < 0 || srcpitch < 0)) {
+ return;
+ }
+
for (y = 0; y < bltheight; y++) {
for (x = 0; x < bltwidth; x+=2) {
p1 = *dst;