From patchwork Thu Jan 23 07:49:43 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: =?utf-8?q?Volker_R=C3=BCmelin?= X-Patchwork-Id: 1227677 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Authentication-Results: ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=nongnu.org (client-ip=209.51.188.17; helo=lists.gnu.org; envelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=t-online.de Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 483DwZ4Fv8z9sSN for ; Thu, 23 Jan 2020 18:50:54 +1100 (AEDT) Received: from localhost ([::1]:52362 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iuXGO-0006DV-1G for incoming@patchwork.ozlabs.org; Thu, 23 Jan 2020 02:50:52 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:46203) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1iuXFe-00064E-Tr for qemu-devel@nongnu.org; Thu, 23 Jan 2020 02:50:07 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1iuXFd-0004k4-Or for qemu-devel@nongnu.org; Thu, 23 Jan 2020 02:50:06 -0500 Received: from mailout11.t-online.de ([194.25.134.85]:52880) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1iuXFd-0004iw-If for qemu-devel@nongnu.org; Thu, 23 Jan 2020 02:50:05 -0500 Received: from fwd28.aul.t-online.de (fwd28.aul.t-online.de [172.20.26.133]) by mailout11.t-online.de (Postfix) with SMTP id AB0C7420CE02; Thu, 23 Jan 2020 08:50:04 +0100 (CET) Received: from linpower.localnet (bHQziOZJ8hihzvynLX2VZ7WNABYdTbkckmy6-wzT15PRNqmXAUFxGBvKiAAcuHcw2P@[46.86.62.122]) by fwd28.t-online.de with (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384 encrypted) esmtp id 1iuXFb-4bEfKa0; Thu, 23 Jan 2020 08:50:03 +0100 Received: by linpower.localnet (Postfix, from userid 1000) id 62E8420109E; Thu, 23 Jan 2020 08:49:43 +0100 (CET) From: =?utf-8?q?Volker_R=C3=BCmelin?= To: Gerd Hoffmann Subject: [PATCH 9/9] audio: audio_generic_get_buffer_in should honor *size Date: Thu, 23 Jan 2020 08:49:43 +0100 Message-Id: <20200123074943.6699-9-vr_qemu@t-online.de> X-Mailer: git-send-email 2.16.4 In-Reply-To: <1e29e1d3-b59b-fcd6-cdff-a680bcdbffa4@t-online.de> References: <1e29e1d3-b59b-fcd6-cdff-a680bcdbffa4@t-online.de> MIME-Version: 1.0 X-ID: bHQziOZJ8hihzvynLX2VZ7WNABYdTbkckmy6-wzT15PRNqmXAUFxGBvKiAAcuHcw2P X-TOI-MSGID: 2e6beee5-9e20-489a-9183-2aa25db3e52f X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 194.25.134.85 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: QEMU , =?utf-8?b?Wm9sdMOhbiBLxZF2w6Fnw7M=?= Errors-To: qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org Sender: "Qemu-devel" The function generic_get_buffer_in currently ignores the *size parameter and may return a buffer larger than *size. As a result the variable samples in function audio_pcm_hw_run_in may underflow. The while loop then most likely will never termiate. This bug was reported at http://bugs.debian.org/948658. Signed-off-by: Volker RĂ¼melin --- audio/audio.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/audio/audio.c b/audio/audio.c index 81822bfec9..f5fb6cbf53 100644 --- a/audio/audio.c +++ b/audio/audio.c @@ -1406,7 +1406,8 @@ void *audio_generic_get_buffer_in(HWVoiceIn *hw, size_t *size) } assert(start >= 0 && start < hw->size_emul); - *size = MIN(hw->pending_emul, hw->size_emul - start); + *size = MIN(*size, hw->pending_emul); + *size = MIN(*size, hw->size_emul - start); return hw->buf_emul + start; }