Skip to content
Commit 89554d2f authored by Prasad J Pandit's avatar Prasad J Pandit Committed by zhanghailiang
Browse files

ati-vga: check mm_index before recursive call (CVE-2020-13800)



While accessing VGA registers via ati_mm_read/write routines,
a guest may set 's->regs.mm_index' such that it leads to infinite
recursion. Check mm_index value to avoid such recursion. Log an
error message for wrong values.

Reported-by: default avatarRen Ding <rding@gatech.edu>
Reported-by: default avatarHanqing Zhao <hanqing@gatech.edu>
Reported-by: default avatarYi Ren <c4tren@gmail.com>
Message-id: 20200604090830.33885-1-ppandit@redhat.com
Suggested-by: default avatarBALATON Zoltan <balaton@eik.bme.hu>
Suggested-by: default avatarPhilippe Mathieu-Daudé <philmd@redhat.com>
Signed-off-by: default avatarPrasad J Pandit <pjp@fedoraproject.org>
Signed-off-by: default avatarGerd Hoffmann <kraxel@redhat.com>
parent a1a9d6f9
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment