From: Cédric Le Goater Date: Thu, 26 Oct 2023 07:06:35 +0000 (+0200) Subject: vfio/pci: Fix buffer overrun when writing the VF token X-Git-Tag: v8.2.0-rc0~29^2~7 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=f8d6f3b16c37bd516a026e92a31dade5d761d3a6;p=thirdparty%2Fqemu.git vfio/pci: Fix buffer overrun when writing the VF token qemu_uuid_unparse() includes a trailing NUL when writing the uuid string and the buffer size should be UUID_FMT_LEN + 1 bytes. Use the recently added UUID_STR_LEN which defines the correct size. Fixes: CID 1522913 Fixes: 2dca1b37a760 ("vfio/pci: add support for VF token") Cc: Alex Williamson Reviewed-by: Alex Williamson Reviewed-by: Juan Quintela Reviewed-by: "Denis V. Lunev" Signed-off-by: Cédric Le Goater --- diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index b27011cee72..c62c02f7b69 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -3081,7 +3081,7 @@ static void vfio_realize(PCIDevice *pdev, Error **errp) struct stat st; int i, ret; bool is_mdev; - char uuid[UUID_FMT_LEN]; + char uuid[UUID_STR_LEN]; char *name; if (!vbasedev->sysfsdev) {