Do not advance past the end of the MADT with a truncated entry, and stop
instead of looping forever when an entry has zero length.
---
i386/i386at/acpi_parse_apic.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/i386/i386at/acpi_parse_apic.c b/i386/i386at/acpi_parse_apic.c
index 0180dfd1..85123015 100644
--- a/i386/i386at/acpi_parse_apic.c
+++ b/i386/i386at/acpi_parse_apic.c
@@ -475,13 +475,19 @@ acpi_apic_parse_table(struct acpi_apic *apic)
/* Initialize number of cpus */
numcpus = apic_get_numcpus();
- /* Search in APIC entry. */
- while ((vm_offset_t)apic_entry < end) {
+ while ((vm_offset_t)apic_entry + sizeof(struct acpi_apic_dhdr) <= end) {
struct acpi_apic_lapic *lapic_entry;
struct acpi_apic_ioapic *ioapic_entry;
struct acpi_apic_irq_override *irq_override_entry;
printf("APIC entry=0x%p end=0x%x\n", apic_entry, end);
+
+ if (apic_entry->length == 0) {
+ printf("APIC: zero-length MADT entry type %#x, stopping\n",
+ apic_entry->type);
+ break;
+ }
+
/* Check entry type. */
switch(apic_entry->type) {