|
From: | Jason Wang |
Subject: | Re: [Qemu-devel] [PATCH] virtio: validate the existence of handle_output before calling it |
Date: | Sun, 15 Feb 2015 02:43:32 +0008 |
On Sat, Feb 14, 2015 at 4:50 AM, Paolo Bonzini <address@hidden> wrote:
On 12/02/2015 04:05, Jason Wang wrote:We don't validate the existence of handle_output which may let a buggyguest to trigger a SIGSEV easily. Fix this by validate its existence before.Cc: address@hiddenCc: Anthony Liguori <address@hidden> Cc: Michael S. Tsirkin <address@hidden> Signed-off-by: Jason Wang <address@hidden>Which queue was causing this? Paolo
The queue that was not used by the device. Though qemu does not use them, but it allows guest to do some basic programming. e.g: (for 1q virtio-net)
1) write 10 to queue_sel 2) setup an arbitrary pfn 3) then notify queue 10
[Prev in Thread] | Current Thread | [Next in Thread] |