KVM: x86: check bounds of APIC maps
authorRadim Krčmář <rkrcmar@redhat.com>
Thu, 27 Nov 2014 22:30:19 +0000 (23:30 +0100)
committerPaolo Bonzini <pbonzini@redhat.com>
Thu, 4 Dec 2014 14:29:08 +0000 (15:29 +0100)
They can't be violated now, but play it safe for the future.

Signed-off-by: Radim Krčmář <rkrcmar@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
arch/x86/kvm/lapic.c

index bd82054..e1940fc 100644 (file)
@@ -193,15 +193,16 @@ static void recalculate_apic_map(struct kvm *kvm)
        kvm_for_each_vcpu(i, vcpu, kvm) {
                struct kvm_lapic *apic = vcpu->arch.apic;
                u16 cid, lid;
-               u32 ldr;
-
-               new->phys_map[kvm_apic_id(apic)] = apic;
+               u32 ldr, aid;
 
+               aid = kvm_apic_id(apic);
                ldr = kvm_apic_get_reg(apic, APIC_LDR);
                cid = apic_cluster_id(new, ldr);
                lid = apic_logical_id(new, ldr);
 
-               if (lid)
+               if (aid < ARRAY_SIZE(new->phys_map))
+                       new->phys_map[aid] = apic;
+               if (lid && cid < ARRAY_SIZE(new->logical_map))
                        new->logical_map[cid][ffs(lid) - 1] = apic;
        }
 out: