On 7/27/26 7:50 AM, Christian Borntraeger wrote: > From: Joshua Daley <[email protected]> > > In the dir_rem[level] == 0 case, level is decremented, then > a virtio_read() is issued on sec_loc[level]. If level is -1, then the > 4 bytes before the static sec_loc array are read, and the virtio_read() > is issued on that garbage block number. > > Guard the call to virtio_read() against the value of level to prevent > this. > > Fixes: 869648e87eeb ("pc-bios/s390-ccw: El Torito 16-bit boot image size > field workaround") > Signed-off-by: Joshua Daley <[email protected]> > Reviewed-by: Christian Borntraeger <[email protected]>
Typo in the RB tag, please fix when applying or if there is a v2! Reviewed-by: Matthew Rosato <[email protected]> > --- > pc-bios/s390-ccw/bootmap.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/pc-bios/s390-ccw/bootmap.c b/pc-bios/s390-ccw/bootmap.c > index 420ee32eff..ed6e8cbbc7 100644 > --- a/pc-bios/s390-ccw/bootmap.c > +++ b/pc-bios/s390-ccw/bootmap.c > @@ -902,7 +902,7 @@ static inline long iso_get_file_size(uint32_t load_rba) > if (dir_rem[level] == 0) { > /* Nothing remaining */ > level--; > - if (virtio_read(sec_loc[level], temp)) { > + if (level >= 0 && virtio_read(sec_loc[level], temp)) { > puts("Failed to read ISO directory"); > return -EIO; > }
