blob: d16b99d570eb7ea25fb4cbdb3fb3de3ffd9435e5 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
|
Out-of-bounds access in smc91c111_receive()
Description of problem:
An out-of-bounds access happens at hw/net/smc91c111.c:705.
`hw/net/smc91c111.c:705:5: runtime error: index -1 out of bounds for type 'int[4]'`
Steps to reproduce:
```
export QEMU_ARGS="-display none -machine accel=qtest, -m 512M -machine realview-eb"
cat << EOF | ./qemu-system-arm $QEMU_ARGS -qtest /dev/null -qtest stdio
writew 0x4e000005 0x227
writel 0x4e00000b 0x25ab1f2
writew 0x4e000000 0xaa6c
clock_step
EOF
```
Additional information:
|