[PATCH v4 0/6] net/eth: Fix stack-buffer-overflow in _eth_get_rss_ex_dst_addr()

Philippe Mathieu-Daudé posted 6 patches 4 years, 8 months ago
Test checkpatch passed
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20210309182709.810955-1-philmd@redhat.com
There is a newer version of this series
net/eth.c                      | 42 +++++++++++++--------------
tests/qtest/fuzz-e1000e-test.c | 53 ++++++++++++++++++++++++++++++++++
MAINTAINERS                    |  1 +
tests/qtest/meson.build        |  1 +
4 files changed, 75 insertions(+), 22 deletions(-)
create mode 100644 tests/qtest/fuzz-e1000e-test.c
[PATCH v4 0/6] net/eth: Fix stack-buffer-overflow in _eth_get_rss_ex_dst_addr()
Posted by Philippe Mathieu-Daudé 4 years, 8 months ago
I had a look at the patch from Miroslav trying to silence a
compiler warning which in fact is a nasty bug. Here is a fix.
https://www.mail-archive.com/qemu-devel@nongnu.org/msg772735.html

Since v3:
- reworked in multiple trivial patches (Stefano)
- reset R-b/A-b tags

Philippe Mathieu-Daudé (6):
  net/eth: Simplify _eth_get_rss_ex_dst_addr()
  net/eth: Better describe _eth_get_rss_ex_dst_addr's offset argument
  net/eth: Initialize input_size variable earlier
  net/eth: Check rt_hdr size before casting to ip6_ext_hdr
  net/eth: Remove now useless size check
  net/eth: Return earlier in _eth_get_rss_ex_dst_addr()

 net/eth.c                      | 42 +++++++++++++--------------
 tests/qtest/fuzz-e1000e-test.c | 53 ++++++++++++++++++++++++++++++++++
 MAINTAINERS                    |  1 +
 tests/qtest/meson.build        |  1 +
 4 files changed, 75 insertions(+), 22 deletions(-)
 create mode 100644 tests/qtest/fuzz-e1000e-test.c

-- 
2.26.2