From nobody Tue Nov 4 18:35:16 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1530632152957680.6048335380292; Tue, 3 Jul 2018 08:35:52 -0700 (PDT) Received: from localhost ([::1]:41136 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1faNLH-0000hW-6H for importer@patchew.org; Tue, 03 Jul 2018 11:35:47 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:33109) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1faNJV-0008E2-9X for qemu-devel@nongnu.org; Tue, 03 Jul 2018 11:33:58 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1faNJU-0001NG-9M for qemu-devel@nongnu.org; Tue, 03 Jul 2018 11:33:57 -0400 Received: from mail-qt0-x243.google.com ([2607:f8b0:400d:c0d::243]:39901) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1faNJU-0001Mz-3h for qemu-devel@nongnu.org; Tue, 03 Jul 2018 11:33:56 -0400 Received: by mail-qt0-x243.google.com with SMTP id q12-v6so1928167qtp.6 for ; Tue, 03 Jul 2018 08:33:56 -0700 (PDT) Received: from x1.local ([138.117.48.222]) by smtp.gmail.com with ESMTPSA id k66-v6sm848715qkc.86.2018.07.03.08.33.53 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 03 Jul 2018 08:33:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=G2ahE2OAFPa8WL+ImNAi6EA+Wl0IRSrivFrhWJ7juV0=; b=c+/KoUnxef1PO0cRKvvcfqVsXOvZ9By+YFObfDjRXpyk8e/gqxlxbonzCTRxJSXvVN r+LdiRg6T744paITi0cyL38HyfWCYLMjM1baKeEzU8v8uwUGwvO5yJVHV8Ax2sBBFKgv EpNU/xVb4j2QY4DlnZtoDm6/mMlcObqzeSNgkkihIClIxdrRcTYbK+iKtBDEgtEkN1Mk CfwQ2Q0pqbHjy5duK7u1q7F7e+RJac645ZnSUFJ5PT9PiDpiDtOBwxCOvR2xThD46GL8 oK+hhiAxZEyCDzTL7C8Mhm2xaixsWD3Yq9ECky2tftXqh696Rpkk7y2KNvWvUDj+hulC +JxQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=G2ahE2OAFPa8WL+ImNAi6EA+Wl0IRSrivFrhWJ7juV0=; b=aQf5Gbh4tCic9TuWDva8cCrEuyOhdMPgIutUBSumYuCrB7g5+26xdfrSAOboyXlG2z 7fJapeB1QdE68VLSyLY1usmA0a06edqYyvZMtieTv6L8sU5nuEDf7KFUr3umOzdXLWrI ykUy6YLycQT4QMX5IRJqYmgyDrGpONj9QlzBcNLzYO9Mk+T8cPKtzEsuhdzf6ibEkcKC IM7TJetWkVBro0ZRnEpmTNSAZu9e/NedBOfMAUFCTyyilIK9g7mI/gCn0dn61/eNXEQw zdqNmqRLa4H4c7bCM1Ic7vB57swP8wiwWutFcsmbaxsqkGpJvdCfeBXGPJVTdF2VJbd+ NP4g== X-Gm-Message-State: APt69E3MF8IyWulTVL/PL7vDJHFpgKA/rBk+b2MHF5e8NGkNrz+nsU9l x5yU6fw/lgsCYszpk/6gVVk= X-Google-Smtp-Source: AAOMgpc0EJDvrWeZx5o/YwWiKcJRWvdvzPhDFukiTJ4rKRfse8ez/VANEMnApCQbNVcsLCDyOl9Wbw== X-Received: by 2002:a0c:d5b0:: with SMTP id g45-v6mr24335119qvi.162.1530632035628; Tue, 03 Jul 2018 08:33:55 -0700 (PDT) From: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= To: Laurent Vivier Date: Tue, 3 Jul 2018 12:33:35 -0300 Message-Id: <20180703153346.9050-2-f4bug@amsat.org> X-Mailer: git-send-email 2.18.0 In-Reply-To: <20180703153346.9050-1-f4bug@amsat.org> References: <20180703153346.9050-1-f4bug@amsat.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2607:f8b0:400d:c0d::243 Subject: [Qemu-devel] [PATCH v4 01/12] linux-user/syscall: Verify recvfrom(addr) is user-writable X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: =?UTF-8?q?Guido=20G=C3=BCnther?= , Riku Voipio , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , qemu-devel@nongnu.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 Signed-off-by: Philippe Mathieu-Daud=C3=A9 Tested-By: Guido G=C3=BCnther Reviewed-by: Laurent Vivier --- linux-user/syscall.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 2117fb13b4..ad40682cee 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -4154,6 +4154,11 @@ static abi_long do_recvfrom(int fd, abi_ulong msg, s= ize_t len, int flags, ret =3D -TARGET_EINVAL; goto fail; } + if (!access_ok(VERIFY_WRITE, target_addr, addrlen)) { + ret =3D -TARGET_EFAULT; + goto fail; + } + addr =3D alloca(addrlen); ret =3D get_errno(safe_recvfrom(fd, host_msg, len, flags, addr, &addrlen)); --=20 2.18.0