[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH v2 2/3] megasas: avoid NULL pointer dereference
From: |
P J P |
Subject: |
Re: [PATCH v2 2/3] megasas: avoid NULL pointer dereference |
Date: |
Tue, 26 May 2020 12:48:25 +0530 (IST) |
Hello,
+-- On Thu, 21 May 2020, Paolo Bonzini wrote --+
| I think the code here was expecting frame_size_p to be 0 if cmd->frame is
| NULL. Can you check why this is not the case, or whether it ever was the
| case?
static MegasasCmd *megasas_enqueue_frame(MegasasState *s, hwaddr frame,
...
int frame_size = MEGASAS_MAX_SGE * sizeof(union mfi_sgl);
hwaddr frame_size_p = frame_size; <== = 128 * 16 = 2048
so 'frame_size_p' always starts with value '2048'
...
cmd->frame = pci_dma_map(pcid, frame, &frame_size_p, 0);
-> pci_dma_map
-> dma_memory_map
-> address_space_map
mr = flatview_translate(fv, addr, &xlat, &l, is_write, attrs);
...
if (atomic_xchg(&bounce.in_use, true)) {
return NULL; <== NULL is returned from here
}
Later when address_space_map() returns 'NULL' above, '*plen' is not set to
zero.
diff --git a/exec.c b/exec.c
index 5162f0d12f..4eea84bf66 100644
--- a/exec.c
+++ b/exec.c
@@ -3538,6 +3538,7 @@ void *address_space_map(AddressSpace *as,
if (!memory_access_is_direct(mr, is_write)) {
if (atomic_xchg(&bounce.in_use, true)) {
+ *plen = 0;
return NULL;
}
I'll send a revised patch above.
Thank you.
--
Prasad J Pandit / Red Hat Product Security Team
8685 545E B54C 486B C6EB 271E E285 8B5A F050 DE8D