diff options
| author | Linfeng Sun <linfeng.sun.dev@gmail.com> | 2026-09-01 17:48:42 +0800 |
|---|---|---|
| committer | Michael S. Tsirkin <mst@redhat.com> | 2026-09-04 17:06:04 -0400 |
| commit | 07074798437d41a91a5b32fea014363ae57f550b (patch) | |
| tree | a4cdc57d3023e3683e9cbe82a649985532afe3ab /scripts/Makefile.thinlto | |
| parent | 8e6ba6992c2f900c9e76dd868d001f53602a32a2 (diff) | |
| download | linux-next-07074798437d41a91a5b32fea014363ae57f550b.tar.gz linux-next-07074798437d41a91a5b32fea014363ae57f550b.zip | |
vdpa_sim_net: check TX pull result before RX copy
vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is
currently added to the unsigned byte counter and then passed as a size_t
length to receive_filter() and vringh_iov_push_iotlb(). A negative error
can therefore become a large length in the RX path.
Handle non-positive pull results before every length use. Count the TX
error and complete the consumed TX descriptor with zero bytes.
I found this bug myself, though the patch was written with AI assistance.
Fixes: cfe226892913 ("vdpa_sim: filter destination mac address")
Assisted-by: OpenAI-Codex:GPT-5
Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260901094842.25875-1-linfeng.sun.dev@gmail.com>
Diffstat (limited to 'scripts/Makefile.thinlto')
0 files changed, 0 insertions, 0 deletions
