diff options
author | Paolo Bonzini <pbonzini@redhat.com> | 2011-12-23 15:39:03 +0100 |
---|---|---|
committer | Anthony Liguori <aliguori@us.ibm.com> | 2012-01-13 10:20:51 -0600 |
commit | 1ba1f2e319afdcb485963cd3f426fdffd1b725f2 (patch) | |
tree | 55412245b45b35211f3efeaae09732311c7ba075 /acl.c | |
parent | 701a8f76aa5243d90a71935982c20c06d8e83b80 (diff) | |
download | qemu-1ba1f2e319afdcb485963cd3f426fdffd1b725f2.zip qemu-1ba1f2e319afdcb485963cd3f426fdffd1b725f2.tar.gz qemu-1ba1f2e319afdcb485963cd3f426fdffd1b725f2.tar.bz2 |
virtio-blk: refuse SG_IO requests with scsi=off
QEMU does have a "scsi" option (to be used like -device
virtio-blk-pci,drive=foo,scsi=off). However, it only
masks the feature bit, and does not reject the command
if a malicious guest disregards the feature bits and
issues a request.
Without this patch, using scsi=off does not protect you
from CVE-2011-4127.
Reviewed-by: Stefan Hajnoczi <stefanha@linux.vnet.ibm.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Anthony Liguori <aliguori@us.ibm.com>
Diffstat (limited to 'acl.c')
0 files changed, 0 insertions, 0 deletions