From nobody Fri Nov 7 12:28:47 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1539211171953539.433227860542; Wed, 10 Oct 2018 15:39:31 -0700 (PDT) Received: from localhost ([::1]:59434 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gAN8T-0003nx-MH for importer@patchew.org; Wed, 10 Oct 2018 18:39:21 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:38753) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1gAN6K-0002de-LR for qemu-devel@nongnu.org; Wed, 10 Oct 2018 18:37:09 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1gAN6H-0000J3-SW for qemu-devel@nongnu.org; Wed, 10 Oct 2018 18:37:08 -0400 Received: from mail-wr1-x433.google.com ([2a00:1450:4864:20::433]:45088) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1gAN6G-0000He-Il for qemu-devel@nongnu.org; Wed, 10 Oct 2018 18:37:05 -0400 Received: by mail-wr1-x433.google.com with SMTP id q5-v6so7443782wrw.12 for ; Wed, 10 Oct 2018 15:37:02 -0700 (PDT) Received: from x1.local (26.red-83-32-208.dynamicip.rima-tde.net. [83.32.208.26]) by smtp.gmail.com with ESMTPSA id q77-v6sm10344886wmd.33.2018.10.10.15.37.00 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 10 Oct 2018 15:37:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=fEw0uDSLDwIMZfcvUYslWjnrnjRK80N6jjjY3n2wgUA=; b=i/TuJ2oYlHA/JFg/e4yxw3glHm0Nq1OyFOHlEcKbun8zJLmk6a0TIO5xix6BxiFaw7 mX3CwgYrgUzP7A7apMuFeb7C2TJqMH4xvssiKc4B723kjDcaARGC7qxaFQtbTYr8ND9x cssV4WfG6MtB0Va79M3FftZaf/ebtiZ2aNvtXGaLOkSN/QTKIWwbjY6du7rxw6p/I0F5 U1i8YfsRUiNHC5ljVZhDhyBWOnon5OcwZ9qf/374WA72h2AsaFpb676zSt1H/yJ1KsYb 3vXVnC5ksUunxKfVvwOsXsznm1V6ZZwTFtub56GOZBb4jTkBdLy02pljVp/v5E1QiOZT dVYQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=fEw0uDSLDwIMZfcvUYslWjnrnjRK80N6jjjY3n2wgUA=; b=deev73gBWqgWykNXeibFdXjxoceLJa8lWnzXEamKvGEZkbAg8z2pjbCbR1Zw6N/CUq I2f6wRJWNlaLryxvd40Op6tZEGhVZz4gp6BXyXQrMSjYABSiAcbiHUFSybGADR96nZPG TK2CG/XsQ07r3oTf6q56/ldb/5eCcFG0C3r2U2j16vb+EG/gKD7M9wBcePtUxWcPWmXn tzOi5CruaWfr1xV5j74/oL9kyn4Ot6VEDwSYBKfQ7bs369Gz0XSjHKgz4OSGXt4CN2wo lnR/G1bZgxcqGNZh3YJUy8aQhxn0PcyAziFXaV2f5Pe6u1R9hmLjvOWWfU2j+SVmVKNm 7exw== X-Gm-Message-State: ABuFfohIfs0VvUg7/xd94k+LTVyesfIww0m4sdxkjekONpJCUHQ3iYJj gRtHT1rVVOyZmjNs+fGehTg= X-Google-Smtp-Source: ACcGV63wvn6aXWSd3kL/mgaV6h1xd0u3cKKAqLQGJ/tnyECMMPix/tArlbVWMLumVcpJY++/t1BNWw== X-Received: by 2002:adf:8425:: with SMTP id 34-v6mr23241843wrf.153.1539211021945; Wed, 10 Oct 2018 15:37:01 -0700 (PDT) From: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= To: Laurent Vivier Date: Thu, 11 Oct 2018 00:36:47 +0200 Message-Id: <20181010223656.31632-2-f4bug@amsat.org> X-Mailer: git-send-email 2.19.1 In-Reply-To: <20181010223656.31632-1-f4bug@amsat.org> References: <20181010223656.31632-1-f4bug@amsat.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2a00:1450:4864:20::433 Subject: [Qemu-devel] [PATCH v5 01/10] linux-user/syscall: Verify recvfrom(addr) is user-writable X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: =?UTF-8?q?Guido=20G=C3=BCnther?= , Riku Voipio , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , qemu-devel@nongnu.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 Signed-off-by: Philippe Mathieu-Daud=C3=A9 Tested-By: Guido G=C3=BCnther Reviewed-by: Laurent Vivier --- linux-user/syscall.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index ae3c0dfef7..ea503381aa 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -2968,6 +2968,11 @@ static abi_long do_recvfrom(int fd, abi_ulong msg, s= ize_t len, int flags, ret =3D -TARGET_EINVAL; goto fail; } + if (!access_ok(VERIFY_WRITE, target_addr, addrlen)) { + ret =3D -TARGET_EFAULT; + goto fail; + } + addr =3D alloca(addrlen); ret =3D get_errno(safe_recvfrom(fd, host_msg, len, flags, addr, &addrlen)); --=20 2.19.1