summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorVolker RĂ¼melin <vr_qemu@t-online.de>2020-07-07 20:08:36 +0200
committerGerd Hoffmann <kraxel@redhat.com>2020-07-13 11:38:40 +0200
commit4f50d4a48e0caa1aad591f3ca437502e33b8699d (patch)
treecba7b4cc0ab62895529c23386f30766fe4910fab
parent9f526fce49c6ac48114ed04914b5a76e4db75785 (diff)
downloadqemu-4f50d4a48e0caa1aad591f3ca437502e33b8699d.zip
ossaudio: fix out of bounds write
In function oss_read() a read error currently does not exit the read loop. With no data to read the variable pos will quickly underflow and a subsequent successful read overwrites memory outside the buffer. This patch adds the missing break statement to the error path of the function. To reproduce start qemu with -audiodev oss,id=audio0 and in the guest start audio recording. After some time this will trigger an exception. Fixes: 3ba4066d08 "ossaudio: port to the new audio backend api" Signed-off-by: Volker RĂ¼melin <vr_qemu@t-online.de> Message-id: 20200707180836.5435-1-vr_qemu@t-online.de Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
-rw-r--r--audio/ossaudio.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/audio/ossaudio.c b/audio/ossaudio.c
index f88d076ec2..a7dcaa31ad 100644
--- a/audio/ossaudio.c
+++ b/audio/ossaudio.c
@@ -691,6 +691,7 @@ static size_t oss_read(HWVoiceIn *hw, void *buf, size_t len)
len, dst);
break;
}
+ break;
}
pos += nread;