From: Gonglei Date: Wed, 20 Aug 2014 05:52:30 +0000 (+0800) Subject: pcihp: fix possible array out of bounds X-Git-Tag: v2.1.1~30 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=bfe3e6f5e3f23cc73dc83b0f4badecd5db175575;p=thirdparty%2Fqemu.git pcihp: fix possible array out of bounds Prevent out-of-bounds array access on acpi_pcihp_pci_status. Signed-off-by: Gonglei Reviewed-by: Peter Crosthwaite Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Cc: qemu-stable@nongnu.org Reviewed-by: Marcel Apfelbaum (cherry picked from commit fa365d7cd11185237471823a5a33d36765454e16) Signed-off-by: Michael Roth --- diff --git a/hw/acpi/pcihp.c b/hw/acpi/pcihp.c index fae663af117..34dedf1e8bf 100644 --- a/hw/acpi/pcihp.c +++ b/hw/acpi/pcihp.c @@ -231,7 +231,7 @@ static uint64_t pci_read(void *opaque, hwaddr addr, unsigned int size) uint32_t val = 0; int bsel = s->hotplug_select; - if (bsel < 0 || bsel > ACPI_PCIHP_MAX_HOTPLUG_BUS) { + if (bsel < 0 || bsel >= ACPI_PCIHP_MAX_HOTPLUG_BUS) { return 0; }