Skip to content

Commit 8704e89

Browse files
zhenywAlex Williamson
authored andcommitted
vfio/pci: Fix OpRegion read
This is to fix incorrect pointer arithmetic which caused wrong OpRegion version returned, then VM driver got error to get wanted VBT block. We need to be safe to return correct data, so force pointer type for byte access. Fixes: 49ba1a2 ("vfio/pci: Add OpRegion 2.0+ Extended VBT support.") Cc: Colin Xu <colin.xu@gmail.com> Cc: Alex Williamson <alex.williamson@redhat.com> Cc: Dmitry Torokhov <dtor@chromium.org> Cc: "Xu, Terrence" <terrence.xu@intel.com> Cc: "Gao, Fred" <fred.gao@intel.com> Acked-by: Colin Xu <colin.xu@gmail.com> Signed-off-by: Zhenyu Wang <zhenyuw@linux.intel.com> Link: https://lore.kernel.org/r/20211125051328.3359902-1-zhenyuw@linux.intel.com [aw: line wrap] Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
1 parent 3b9a2d5 commit 8704e89

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

drivers/vfio/pci/vfio_pci_igd.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,8 @@ static ssize_t vfio_pci_igd_rw(struct vfio_pci_core_device *vdev,
9898
version = cpu_to_le16(0x0201);
9999

100100
if (igd_opregion_shift_copy(buf, &off,
101-
&version + (pos - OPREGION_VERSION),
101+
(u8 *)&version +
102+
(pos - OPREGION_VERSION),
102103
&pos, &remaining, bytes))
103104
return -EFAULT;
104105
}
@@ -121,7 +122,7 @@ static ssize_t vfio_pci_igd_rw(struct vfio_pci_core_device *vdev,
121122
OPREGION_SIZE : 0);
122123

123124
if (igd_opregion_shift_copy(buf, &off,
124-
&rvda + (pos - OPREGION_RVDA),
125+
(u8 *)&rvda + (pos - OPREGION_RVDA),
125126
&pos, &remaining, bytes))
126127
return -EFAULT;
127128
}

0 commit comments

Comments
 (0)