mirror of https://github.com/xemu-project/xemu.git
linux-user: Detect Negative Message Sizes in msgsnd System Call
The msgsnd system call takes an argument that describes the message size (msgsz) and is of type size_t. The system call should set errno to EINVAL in the event that a negative message size is passed. Signed-off-by: Tom Musta <tommusta@gmail.com> Reviewed-by: Peter Maydell <peter.maydell@linaro.org> Signed-off-by: Riku Voipio <riku.voipio@linaro.org>
This commit is contained in:
parent
b6ce1f6b90
commit
edcc5f9dc3
|
@ -2879,12 +2879,16 @@ struct target_msgbuf {
|
||||||
};
|
};
|
||||||
|
|
||||||
static inline abi_long do_msgsnd(int msqid, abi_long msgp,
|
static inline abi_long do_msgsnd(int msqid, abi_long msgp,
|
||||||
unsigned int msgsz, int msgflg)
|
ssize_t msgsz, int msgflg)
|
||||||
{
|
{
|
||||||
struct target_msgbuf *target_mb;
|
struct target_msgbuf *target_mb;
|
||||||
struct msgbuf *host_mb;
|
struct msgbuf *host_mb;
|
||||||
abi_long ret = 0;
|
abi_long ret = 0;
|
||||||
|
|
||||||
|
if (msgsz < 0) {
|
||||||
|
return -TARGET_EINVAL;
|
||||||
|
}
|
||||||
|
|
||||||
if (!lock_user_struct(VERIFY_READ, target_mb, msgp, 0))
|
if (!lock_user_struct(VERIFY_READ, target_mb, msgp, 0))
|
||||||
return -TARGET_EFAULT;
|
return -TARGET_EFAULT;
|
||||||
host_mb = malloc(msgsz+sizeof(long));
|
host_mb = malloc(msgsz+sizeof(long));
|
||||||
|
|
Loading…
Reference in New Issue