3430f55120
Refine the reproducible build changes to no longer override linux commands, but rather fix via patches only. Also fix all the recent security issues reported. OBS-URL: https://build.opensuse.org/request/show/441247 OBS-URL: https://build.opensuse.org/package/show/Virtualization/qemu?expand=0&rev=320
37 lines
1.4 KiB
Diff
37 lines
1.4 KiB
Diff
From eccd42e2e97bdf76467d48b0cecdd07327c686fd Mon Sep 17 00:00:00 2001
|
|
From: Prasad J Pandit <pjp@fedoraproject.org>
|
|
Date: Wed, 31 Aug 2016 17:36:07 +0530
|
|
Subject: [PATCH] scsi: mptconfig: fix an assert expression
|
|
|
|
When LSI SAS1068 Host Bus emulator builds configuration page
|
|
headers, mptsas_config_pack() should assert that the size
|
|
fits in a byte. However, the size is expressed in 32-bit
|
|
units, so up to 1020 bytes fit. The assertion was only
|
|
allowing replies up to 252 bytes, so fix it.
|
|
|
|
Suggested-by: Paolo Bonzini <pbonzini@redhat.com>
|
|
Signed-off-by: Prasad J Pandit <pjp@fedoraproject.org>
|
|
Message-Id: <1472645167-30765-2-git-send-email-ppandit@redhat.com>
|
|
Cc: qemu-stable@nongnu.org
|
|
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
|
(cherry picked from commit cf2bce203a45d7437029d108357fb23fea0967b6)
|
|
[BR: CVE-2016-7157 BSC#997860]
|
|
Signed-off-by: Bruce Rogers <brogers@suse.com>
|
|
---
|
|
hw/scsi/mptconfig.c | 2 +-
|
|
1 file changed, 1 insertion(+), 1 deletion(-)
|
|
|
|
diff --git a/hw/scsi/mptconfig.c b/hw/scsi/mptconfig.c
|
|
index 7071854..3e4f400 100644
|
|
--- a/hw/scsi/mptconfig.c
|
|
+++ b/hw/scsi/mptconfig.c
|
|
@@ -158,7 +158,7 @@ static size_t mptsas_config_pack(uint8_t **data, const char *fmt, ...)
|
|
va_end(ap);
|
|
|
|
if (data) {
|
|
- assert(ret < 256 && (ret % 4) == 0);
|
|
+ assert(ret / 4 < 256 && (ret % 4) == 0);
|
|
stb_p(*data + 1, ret / 4);
|
|
}
|
|
return ret;
|