Bug 725007 - xen: off by one errors in multicalls.c
Summary: xen: off by one errors in multicalls.c
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: kernel
Version: 6.2
Hardware: Unspecified
OS: Linux
unspecified
low
Target Milestone: rc
: ---
Assignee: Radim Krčmář
QA Contact: Virtualization Bugs
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-07-22 14:58 UTC by Radim Krčmář
Modified: 2011-12-06 13:53 UTC (History)
3 users (show)

Fixed In Version: kernel-2.6.32-176.el6
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-12-06 13:53:43 UTC
Target Upstream Version:


Attachments (Terms of Use)
xen: off by one errors in multicalls.c (1.79 KB, patch)
2011-07-22 14:58 UTC, Radim Krčmář
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2011:1530 0 normal SHIPPED_LIVE Moderate: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update 2011-12-06 01:45:35 UTC

Description Radim Krčmář 2011-07-22 14:58:39 UTC
Created attachment 514718 [details]
xen: off by one errors in multicalls.c

Cherry-pick f124c6ae59e193705c9ddac57684d50006d710e6 from upstream.
Original commit message:
    xen: off by one errors in multicalls.c
    
    b->args[] has MC_ARGS elements, so the comparison here should be
    ">=" instead of ">".  Otherwise we read past the end of the array
    one space.
    
    CC: stable
    Signed-off-by: Dan Carpenter <error27>
    Signed-off-by: Konrad Rzeszutek Wilk <konrad.wilk>
    Signed-off-by: Jeremy Fitzhardinge <jeremy.fitzhardinge>

Does not happen in rhel6 tree, but better be safe.

Comment 4 Aristeu Rozanski 2011-08-02 13:58:09 UTC
Patch(es) available on kernel-2.6.32-176.el6

Comment 9 errata-xmlrpc 2011-12-06 13:53:43 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2011-1530.html


Note You need to log in before you can comment on or make changes to this bug.