From: Radim Krčmář Date: Thu, 27 Nov 2014 22:30:19 +0000 (+0100) Subject: KVM: x86: check bounds of APIC maps X-Git-Tag: v3.19-rc1~36^2~28 X-Git-Url: https://openfabrics.org/gitweb/?a=commitdiff_plain;h=25995e5b4aa308e5264cf7cf3e86871acf6a8b8c;p=~emulex%2Finfiniband.git KVM: x86: check bounds of APIC maps They can't be violated now, but play it safe for the future. Signed-off-by: Radim Krčmář Signed-off-by: Paolo Bonzini --- diff --git a/arch/x86/kvm/lapic.c b/arch/x86/kvm/lapic.c index bd82054664f..e1940fccaf6 100644 --- a/arch/x86/kvm/lapic.c +++ b/arch/x86/kvm/lapic.c @@ -193,15 +193,16 @@ static void recalculate_apic_map(struct kvm *kvm) kvm_for_each_vcpu(i, vcpu, kvm) { struct kvm_lapic *apic = vcpu->arch.apic; u16 cid, lid; - u32 ldr; - - new->phys_map[kvm_apic_id(apic)] = apic; + u32 ldr, aid; + aid = kvm_apic_id(apic); ldr = kvm_apic_get_reg(apic, APIC_LDR); cid = apic_cluster_id(new, ldr); lid = apic_logical_id(new, ldr); - if (lid) + if (aid < ARRAY_SIZE(new->phys_map)) + new->phys_map[aid] = apic; + if (lid && cid < ARRAY_SIZE(new->logical_map)) new->logical_map[cid][ffs(lid) - 1] = apic; } out: