<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">From 5d8d0294238f471508c2929856b95b65530964ba Mon Sep 17 00:00:00 2001
Message-Id: &lt;5d8d0294238f471508c2929856b95b65530964ba.1350312451.git.minovotn@redhat.com&gt;
In-Reply-To: &lt;aa2da19f266f7dd7345db5620ee362446fc6e806.1350312451.git.minovotn@redhat.com&gt;
References: &lt;aa2da19f266f7dd7345db5620ee362446fc6e806.1350312451.git.minovotn@redhat.com&gt;
From: Alon Levy &lt;alevy@redhat.com&gt;
Date: Sun, 7 Oct 2012 15:31:46 +0200
Subject: [PATCH 09/27] qxl: Slot sanity check in qxl_phys2virt() is off by
 one, fix

RH-Author: Alon Levy &lt;alevy@redhat.com&gt;
Message-id: &lt;1349623920-19894-3-git-send-email-alevy@redhat.com&gt;
Patchwork-id: 42777
O-Subject: [PATCH RHEL-6.4 v2 02/16] qxl: Slot sanity check in qxl_phys2virt() is off by one, fix
Bugzilla: 770842
RH-Acked-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;
RH-Acked-by: Paolo Bonzini &lt;pbonzini@redhat.com&gt;
RH-Acked-by: Arnon Gilboa &lt;agilboa@redhat.com&gt;

From: Markus Armbruster &lt;armbru@redhat.com&gt;

Spotted by Coverity.

Signed-off-by: Markus Armbruster &lt;armbru@redhat.com&gt;
Signed-off-by: Gerd Hoffmann &lt;kraxel@redhat.com&gt;

Upstream: 6b7332eb4013fec6ad294115ab889d77d4463624
---
 hw/qxl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Signed-off-by: Michal Novotny &lt;minovotn@redhat.com&gt;
---
 hw/qxl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/qxl.c b/hw/qxl.c
index 5bcddc2..aef3486 100644
--- a/hw/qxl.c
+++ b/hw/qxl.c
@@ -1160,7 +1160,7 @@ void *qxl_phys2virt(PCIQXLDevice *qxl, QXLPHYSICAL pqxl, int group_id)
     case MEMSLOT_GROUP_HOST:
         return (void*)offset;
     case MEMSLOT_GROUP_GUEST:
-        PANIC_ON(slot &gt; NUM_MEMSLOTS);
+        PANIC_ON(slot &gt;= NUM_MEMSLOTS);
         PANIC_ON(!qxl-&gt;guest_slots[slot].active);
         PANIC_ON(offset &lt; qxl-&gt;guest_slots[slot].delta);
         offset -= qxl-&gt;guest_slots[slot].delta;
-- 
1.7.11.7

</pre></body></html>