On Thu,  7 Jun 2018 17:47:05 +0200
David Hildenbrand <da...@redhat.com> wrote:

> Right now we can crash QEMU using e.g.
> 
> qemu-system-x86_64 -m 256M,maxmem=20G,slots=2 \
>  -object 
> memory-backend-file,id=mem0,size=12288,mem-path=/dev/zero,align=12288 \
>  -device pc-dimm,id=dimm1,memdev=mem0
> 
> qemu-system-x86_64: util/mmap-alloc.c:115:
>  qemu_ram_mmap: Assertion `is_power_of_2(align)' failed
> 
> Fix this by adding a proper check.
> 
> Signed-off-by: David Hildenbrand <da...@redhat.com>
Reviewed-by: Igor Mammedov <imamm...@redhat.com>

> ---
>  exec.c | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/exec.c b/exec.c
> index f6645ede0c..f54c83ac61 100644
> --- a/exec.c
> +++ b/exec.c
> @@ -1681,6 +1681,10 @@ static void *file_ram_alloc(RAMBlock *block,
>                     " must be multiples of page size 0x%zx",
>                     block->mr->align, block->page_size);
>          return NULL;
> +    } else if (block->mr->align && !is_power_of_2(block->mr->align)) {
> +        error_setg(errp, "alignment 0x%" PRIx64
> +                   " must be a power of two", block->mr->align);
> +        return NULL;
>      }
>      block->mr->align = MAX(block->page_size, block->mr->align);
>  #if defined(__s390x__)


Reply via email to