From: P J P Date: Mon, 21 Dec 2015 09:43:13 +0000 (+0530) Subject: scsi: initialise info object with appropriate size X-Git-Tag: v2.5.1~42 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=16a28757355514e49507167c9aaae76964fbc793;p=thirdparty%2Fqemu.git scsi: initialise info object with appropriate size While processing controller 'CTRL_GET_INFO' command, the routine 'megasas_ctrl_get_info' overflows the '&info' object size. Use its appropriate size to null initialise it. Reported-by: Qinghao Tang Signed-off-by: Prasad J Pandit Message-Id: Cc: qemu-stable@nongnu.org Signed-off-by: Paolo Bonzini Signed-off-by: P J P (cherry picked from commit 36fef36b91f7ec0435215860f1458b5342ce2811) Signed-off-by: Michael Roth --- diff --git a/hw/scsi/megasas.c b/hw/scsi/megasas.c index d7dc6672ecd..576f56cbf29 100644 --- a/hw/scsi/megasas.c +++ b/hw/scsi/megasas.c @@ -718,7 +718,7 @@ static int megasas_ctrl_get_info(MegasasState *s, MegasasCmd *cmd) BusChild *kid; int num_pd_disks = 0; - memset(&info, 0x0, cmd->iov_size); + memset(&info, 0x0, dcmd_size); if (cmd->iov_size < dcmd_size) { trace_megasas_dcmd_invalid_xfer_len(cmd->index, cmd->iov_size, dcmd_size);