From nobody Tue Nov 4 18:52:26 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (208.118.235.17 [208.118.235.17]) by mx.zohomail.com with SMTPS id 1530553979536669.9304704335914; Mon, 2 Jul 2018 10:52:59 -0700 (PDT) Received: from localhost ([::1]:34650 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fa30L-0005vo-Fz for importer@patchew.org; Mon, 02 Jul 2018 13:52:49 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:60466) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fa2yK-0004xK-25 for qemu-devel@nongnu.org; Mon, 02 Jul 2018 13:50:44 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fa2yI-0003ZI-Ce for qemu-devel@nongnu.org; Mon, 02 Jul 2018 13:50:44 -0400 Received: from mail-vk0-x22b.google.com ([2607:f8b0:400c:c05::22b]:46793) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fa2yI-0003Yz-7b for qemu-devel@nongnu.org; Mon, 02 Jul 2018 13:50:42 -0400 Received: by mail-vk0-x22b.google.com with SMTP id b14-v6so3980872vke.13 for ; Mon, 02 Jul 2018 10:50:42 -0700 (PDT) Received: from x1.local ([138.117.48.222]) by smtp.gmail.com with ESMTPSA id j22-v6sm993152uag.15.2018.07.02.10.50.39 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 02 Jul 2018 10:50:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=G2ahE2OAFPa8WL+ImNAi6EA+Wl0IRSrivFrhWJ7juV0=; b=pV1Vfz7NkYQ5SrtdhUbef2MqW+FJTLoD5G+ytrXfCvg7n/kQhbfB1Zaz4cyDPujjeD dIYbu++5fCtNzPsvYMuM+THIGwkPWSVPJi++ID/oTNsRBpyEM+Z7YX3ur7TgaFiY46E/ Xv6M8KL49mFkMQqS/Ujo7d4/pVRiPcNcJUxVJgBlRn3a2pvBsQgpoNoWqkLavmFppjvV KxKlYuc1m1FflNCvG9j9Fvgvb0kuySSdHn1ByleyeVVa4hqDYRssXw80xy9qHki3itdi ZPILrkvvpM26+uvlBoTfUjtPqunwGnE20syYFXaVGjUwWlLgNU413ZoM+BXqLzjy9Vut fz8w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=G2ahE2OAFPa8WL+ImNAi6EA+Wl0IRSrivFrhWJ7juV0=; b=ST4fAodRjG8i93ask7dtgwFAkCkq4NNFhGNs8Z5j5F1obcqJjnseaUDyIBonzjIuIR dbhRw1UnSbGRUaroM2fvTkNUGJ6Gav4UPb1zMswfR0927fox0b0tnEdVsV+Hym5OlWpA GxnJLZ+Kfvrk1c+WLEkCUGajKgqHwF7Bd5jaZ7WeO8BwgeiY5U65arp0cnsT4kpLy04G N3xELP9/9K+giFxeRhE7mYQR8ZlG5lDJMKPui805E2ihBKfwH6rs52A7O9VvLcaS8EIe 8NJbCeal+J4jCOQb7uTTgx9D03JGRCIHKpzRk9tYJ+codzSaQyY/9M+qHjuh0/T9sfhN tZXQ== X-Gm-Message-State: APt69E1/JaNyHh++qkdbtkOLgF6w5fVGtOS7iiVoVtneYTFlCb5aIBPG sThiv690WlFfUZhzT5D3KL0= X-Google-Smtp-Source: AAOMgpefMFjAbJvzAzzcz559xxRV6HPL09YP8ffKHUT7U5lN5deLC8FgYlwAVjr1Pnl9+qWupQCyZA== X-Received: by 2002:a1f:f0a:: with SMTP id 10-v6mr15254232vkp.178.1530553841613; Mon, 02 Jul 2018 10:50:41 -0700 (PDT) From: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= To: Laurent Vivier Date: Mon, 2 Jul 2018 14:50:18 -0300 Message-Id: <20180702175030.18621-2-f4bug@amsat.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180702175030.18621-1-f4bug@amsat.org> References: <20180702175030.18621-1-f4bug@amsat.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2607:f8b0:400c:c05::22b Subject: [Qemu-devel] [PATCH v3 01/13] linux-user/syscall: Verify recvfrom(addr) is user-writable X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: =?UTF-8?q?Guido=20G=C3=BCnther?= , Riku Voipio , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , qemu-devel@nongnu.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 Signed-off-by: Philippe Mathieu-Daud=C3=A9 Tested-By: Guido G=C3=BCnther Reviewed-by: Laurent Vivier --- linux-user/syscall.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 2117fb13b4..ad40682cee 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -4154,6 +4154,11 @@ static abi_long do_recvfrom(int fd, abi_ulong msg, s= ize_t len, int flags, ret =3D -TARGET_EINVAL; goto fail; } + if (!access_ok(VERIFY_WRITE, target_addr, addrlen)) { + ret =3D -TARGET_EFAULT; + goto fail; + } + addr =3D alloca(addrlen); ret =3D get_errno(safe_recvfrom(fd, host_msg, len, flags, addr, &addrlen)); --=20 2.18.0