From: Doug Cook <[email protected]>
TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and
ax3000_class_init() writes to it:
Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc);
sc->num_cpus = AX3000_NUM_CPUS;
but its TypeInfo omits .class_size, so type_initialize() only allocates
class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass).
The store to sc->num_cpus therefore writes 4 bytes of the value 4 just
past the end of the class allocation, corrupting whatever heap block
follows it.
Fix by setting class_size.
Fixes: 33a71a68c6e1 ("hw/arm: Add Axiado SoC AX3000")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197
Signed-off-by: Doug Cook <[email protected]>
Message-id:
lvxpr21mb70090b04ff7397b0f2a201c8ad...@lvxpr21mb7009.namprd21.prod.outlook.com
Reviewed-by: Peter Maydell <[email protected]>
Signed-off-by: Peter Maydell <[email protected]>
---
hw/arm/ax3000-soc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/hw/arm/ax3000-soc.c b/hw/arm/ax3000-soc.c
index 71e31c6fb46..ebe174fb978 100644
--- a/hw/arm/ax3000-soc.c
+++ b/hw/arm/ax3000-soc.c
@@ -236,6 +236,7 @@ static const TypeInfo axiado_soc_types[] = {
.instance_size = sizeof(Ax3000SoCState),
.instance_init = ax3000_init,
.class_init = ax3000_class_init,
+ .class_size = sizeof(Ax3000SoCClass),
}
};
--
2.43.0