Gerd Hoffmann
23ba9f170f
uas: add stream number sanity checks.
...
The device uses the guest-supplied stream number unchecked, which can
lead to guest-triggered out-of-band access to the UASDevice->data3 and
UASDevice->status3 fields. Add the missing checks.
Fixes: CVE-2021-3713
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
Reported-by: Chen Zhe <chenzhe@huawei.com>
Reported-by: Tan Jingguo <tanjingguo@huawei.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@redhat.com>
Message-Id: <20210818120505.1258262-2-kraxel@redhat.com>
(cherry picked from commit 13b250b12ad3c59114a6a17d59caf073ce45b33a)
Signed-off-by: Michael Roth <michael.roth@amd.com>
2021-12-14 08:56:53 -06:00
..
2021-03-15 17:00:58 +01:00
2021-07-09 18:20:27 +02:00
2021-07-09 18:20:27 +02:00
2020-09-18 14:12:32 -04:00
2021-05-02 17:24:50 +02:00
2021-05-05 15:06:01 +02:00
2021-01-22 14:51:35 +01:00
2021-07-09 18:42:46 +02:00
2018-06-01 19:20:38 +03:00
2016-02-23 12:43:05 +00:00
2021-03-15 17:00:58 +01:00
2021-05-04 08:38:23 +02:00
2021-01-08 15:13:38 +00:00
2021-06-14 13:28:50 +01:00
2020-09-18 14:12:32 -04:00
2021-03-15 17:00:58 +01:00
2021-05-02 17:24:50 +02:00
2021-07-09 18:21:33 +02:00
2021-07-09 18:21:33 +02:00
2021-03-15 17:01:17 +01:00
2021-12-14 08:56:53 -06:00
2021-05-04 08:38:23 +02:00
2020-10-19 09:17:21 +02:00
2020-09-18 14:12:32 -04:00
2021-05-02 17:24:50 +02:00
2020-05-15 07:08:14 +02:00
2021-03-26 09:14:48 +01:00
2021-03-26 11:10:49 +01:00
2020-10-27 11:10:21 +00:00
2020-06-12 11:20:15 -04:00
2021-01-08 15:13:38 +00:00
2021-03-09 21:19:10 +01:00
2020-09-18 14:12:32 -04:00
2021-03-15 17:00:59 +01:00
2021-03-15 17:00:59 +01:00
2020-11-15 16:40:48 +01:00
2021-05-28 09:10:20 +02:00
2020-11-15 16:40:48 +01:00
2021-05-28 09:10:20 +02:00
2020-10-21 11:36:19 +02:00
2021-05-28 09:10:20 +02:00
2021-05-28 09:10:20 +02:00
2021-07-29 11:18:24 +02:00
2013-02-19 12:30:05 +01:00
2021-05-02 17:24:50 +02:00
2021-03-15 17:01:12 +01:00
2019-08-16 13:31:52 +02:00
2021-07-22 14:44:47 +02:00
2021-02-17 14:29:12 +01:00
2021-05-12 18:20:25 +02:00
2013-01-08 10:56:58 +01:00
2020-03-16 23:02:25 +01:00
2021-05-12 18:20:25 +02:00
2021-08-05 16:15:33 +04:00
2021-06-02 06:51:09 +02:00
2020-08-21 06:18:24 -04:00
2020-09-18 14:12:32 -04:00
2020-09-21 09:44:54 +02:00
2021-02-20 12:36:19 +01:00
2021-03-15 17:00:58 +01:00
2020-08-31 08:10:47 +02:00
2021-03-15 17:00:59 +01:00
2021-05-02 17:24:50 +02:00
2021-05-02 17:24:50 +02:00
2021-05-02 17:24:50 +02:00