Skip to content

rtl8169: Fix IDR4 out-of-bounds read, snapshot the MAC address - #321

Open
BeastLe9enD wants to merge 2 commits into
LekKit:stagingfrom
ProjectKML:rtl8169-mac-fixes
Open

BeastLe9enD wants to merge 2 commits into
LekKit:stagingfrom
ProjectKML:rtl8169-mac-fixes

Conversation

@BeastLe9enD

Copy link
Copy Markdown

Two small fixes around the MAC address handling in the RTL8169 model.

  • rtl8169_pci_read() reads IDR0/IDR4 from a six-byte mac[] buffer.
    The IDR4 case does a 32-bit read at offset 4, which runs two bytes
    past the end of the array. Pad the buffer to eight bytes.
  • rtl8169_suspend() already snapshots the EEPROM, but not the MAC
    address the TAP device was created with. After resuming a snapshot on
    a fresh TAP device the guest keeps using the address it read at boot,
    while the TAP now answers to a different one. Store the address in
    the snapshot and push it back into the TAP device on resume, next to
    the existing EEPROM snapshot.

An IDR4 read fetches four bytes starting at offset 4 of the six-byte
MAC address, so the read went two bytes past the buffer.
The guest keeps using the MAC address it read at boot, so restore it
on the TAP device when resuming a snapshot instead of keeping whatever
address the new TAP device came up with.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant