red_worker.c: fix memory corruption when data from client is bigger than 1024 bytes

Previously, there was no check for the size of the message received from
the client, and all messages were read into a buffer of size 1024.
However, migration data can be bigger than 1024. In such cases, memory
corruption occurred.
This commit is contained in:
Yonit Halperin 2012-11-16 15:11:54 -05:00
parent 16b38ec84e
commit 4c1a2ad3f1

View File

@ -1597,12 +1597,24 @@ static uint8_t *common_alloc_recv_buf(RedChannelClient *rcc, uint16_t type, uint
{
CommonChannel *common = SPICE_CONTAINEROF(rcc->channel, CommonChannel, base);
/* SPICE_MSGC_MIGRATE_DATA is the only client message whose size is dynamic */
if (type == SPICE_MSGC_MIGRATE_DATA) {
return spice_malloc(size);
}
if (size > RECIVE_BUF_SIZE) {
spice_critical("unexpected message size %u (max is %d)", size, RECIVE_BUF_SIZE);
return NULL;
}
return common->recv_buf;
}
static void common_release_recv_buf(RedChannelClient *rcc, uint16_t type, uint32_t size,
uint8_t* msg)
{
if (type == SPICE_MSGC_MIGRATE_DATA) {
free(msg);
}
}
#define CLIENT_PIXMAPS_CACHE