[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Qemu-stable] [Qemu-devel] [PATCH v2] vmdk: Fix vmdk_parse_extents
From: |
Fam Zheng |
Subject: |
Re: [Qemu-stable] [Qemu-devel] [PATCH v2] vmdk: Fix vmdk_parse_extents |
Date: |
Mon, 14 Oct 2013 09:57:08 +0800 |
User-agent: |
Mutt/1.5.21 (2010-09-15) |
Cc'ing address@hidden
On Fri, 10/11 19:48, Fam Zheng wrote:
> An extra 'p++' after while loop when *p == '\n' will move p to unknown
> data position, risking parsing junk data or memory access violation.
>
> Cc: address@hidden
> Signed-off-by: Fam Zheng <address@hidden>
> ---
> block/vmdk.c | 7 +++++--
> 1 file changed, 5 insertions(+), 2 deletions(-)
>
> diff --git a/block/vmdk.c b/block/vmdk.c
> index 5d56e31..21f0fa7 100644
> --- a/block/vmdk.c
> +++ b/block/vmdk.c
> @@ -760,10 +760,13 @@ static int vmdk_parse_extents(const char *desc,
> BlockDriverState *bs,
> }
> next_line:
> /* move to next line */
> - while (*p && *p != '\n') {
> + while (*p) {
> + if (*p == '\n') {
> + p++;
> + break;
> + }
> p++;
> }
> - p++;
> }
> return 0;
> }
> --
> 1.8.3.1
>
>
[Prev in Thread] |
Current Thread |
[Next in Thread] |
- Re: [Qemu-stable] [Qemu-devel] [PATCH v2] vmdk: Fix vmdk_parse_extents,
Fam Zheng <=