git: 867aaad5c2bf - stable/13 - bhyve: validate corb->wp to avoid infinite loop
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 24 Sep 2024 22:53:13 UTC
The branch stable/13 has been updated by emaste:
URL: https://cgit.FreeBSD.org/src/commit/?id=867aaad5c2bfdd8326fc805964e711ccfbb18d1e
commit 867aaad5c2bfdd8326fc805964e711ccfbb18d1e
Author: Ed Maste <emaste@FreeBSD.org>
AuthorDate: 2024-09-19 18:57:42 +0000
Commit: Ed Maste <emaste@FreeBSD.org>
CommitDate: 2024-09-24 17:31:09 +0000
bhyve: validate corb->wp to avoid infinite loop
Guests must set HDAC_CORBWP less than corb->size. Treat invalid values
as an error rather than entering an infinite loop.
Reported by: Synacktiv
Reviewed by: markj
Security: HYP-12
Sponsored by: The Alpha-Omega Project
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D46134
(cherry picked from commit a305f44d1404fbf386bb2b50ab7233ce9eabe0bb)
(cherry picked from commit 6a645bb3535cb73b1f20db652c9e3893f26a986e)
---
usr.sbin/bhyve/pci_hda.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/usr.sbin/bhyve/pci_hda.c b/usr.sbin/bhyve/pci_hda.c
index 7d824d7a1fd8..fd47abebaa42 100644
--- a/usr.sbin/bhyve/pci_hda.c
+++ b/usr.sbin/bhyve/pci_hda.c
@@ -787,6 +787,11 @@ hda_corb_run(struct hda_softc *sc)
int err;
corb->wp = hda_get_reg_by_offset(sc, HDAC_CORBWP);
+ if (corb->wp >= corb->size) {
+ DPRINTF("Invalid HDAC_CORBWP %u >= size %u", corb->wp,
+ corb->size);
+ return (-1);
+ }
while (corb->rp != corb->wp && corb->run) {
corb->rp++;