Good observation.

Reviewed-by: Star Zeng <star.z...@intel.com>


Thanks,
Star
-----Original Message-----
From: Marcin Wojtas [mailto:m...@semihalf.com] 
Sent: Wednesday, September 26, 2018 5:58 AM
To: edk2-devel@lists.01.org
Cc: Tian, Feng <feng.t...@intel.com>; Kinney, Michael D 
<michael.d.kin...@intel.com>; Gao, Liming <liming....@intel.com>; 
leif.lindh...@linaro.org; ard.biesheu...@linaro.org; nad...@marvell.com; 
m...@semihalf.com; j...@semihalf.com; j...@semihalf.com; Ni, Ruiyu 
<ruiyu...@intel.com>; Wang, Fei1 <fei1.w...@intel.com>; Zeng, Star 
<star.z...@intel.com>
Subject: [PATCH v2] MdeModulePkg: XhciDxe: Prevent illegal memory access in 
XhcSetHsee

REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1206

Newly added XhcSetHsee() routine reads 4 bytes into a UINT16 variable causing 
issues on PCIE and NonDiscoverable Xhci controllers. Fix that.

Cc: Ruiyu Ni <ruiyu...@intel.com>
Cc: Fei1 Wang <fei1.w...@intel.com>
Cc: Star Zeng <star.z...@intel.com>
Contributed-under: TianoCore Contribution Agreement 1.1
Signed-off-by: Marcin Wojtas <m...@semihalf.com>
---
 MdeModulePkg/Bus/Pci/XhciDxe/XhciReg.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/MdeModulePkg/Bus/Pci/XhciDxe/XhciReg.c 
b/MdeModulePkg/Bus/Pci/XhciDxe/XhciReg.c
index 89f073e..3ed1a55 100644
--- a/MdeModulePkg/Bus/Pci/XhciDxe/XhciReg.c
+++ b/MdeModulePkg/Bus/Pci/XhciDxe/XhciReg.c
@@ -609,7 +609,7 @@ XhcSetHsee (
                         PciIo,
                         EfiPciIoWidthUint16,
                         PCI_COMMAND_OFFSET,
-                        sizeof (XhciCmd),
+                        sizeof (XhciCmd) / sizeof (UINT16),
                         &XhciCmd
                         );
   if (!EFI_ERROR (Status)) {
--
2.7.4

_______________________________________________
edk2-devel mailing list
edk2-devel@lists.01.org
https://lists.01.org/mailman/listinfo/edk2-devel

Reply via email to