From: Philippe Mathieu-Daudé Date: Thu, 6 Aug 2020 13:09:45 +0000 (+0200) Subject: hw/core/sysbus: Assert memory region index is in range X-Git-Tag: v5.2.0-rc0~146^2~28 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=f234501c67234d54dc75f34eb76988c929778070;p=thirdparty%2Fqemu.git hw/core/sysbus: Assert memory region index is in range Devices incorrectly modelled might use invalid index while calling sysbus_mmio_get_region(), leading to OOB access. Help developers by asserting the index is in range. Signed-off-by: Philippe Mathieu-Daudé Reviewed-by: Richard Henderson Message-Id: <20200806130945.21629-3-f4bug@amsat.org> Signed-off-by: Laurent Vivier --- diff --git a/hw/core/sysbus.c b/hw/core/sysbus.c index 77ab351ce1a..294f90b7dee 100644 --- a/hw/core/sysbus.c +++ b/hw/core/sysbus.c @@ -199,6 +199,7 @@ void sysbus_init_mmio(SysBusDevice *dev, MemoryRegion *memory) MemoryRegion *sysbus_mmio_get_region(SysBusDevice *dev, int n) { + assert(n >= 0 && n < QDEV_MAX_MMIO); return dev->mmio[n].memory; }