rtl8139: check TCP Data Offset field (CVE-2015-5165)
commit8357946b15f0a31f73dd691b7da95f29318ed310
authorStefan Hajnoczi <stefanha@redhat.com>
Wed, 15 Jul 2015 16:39:29 +0000 (15 17:39 +0100)
committerStefan Hajnoczi <stefanha@redhat.com>
Mon, 3 Aug 2015 12:08:10 +0000 (3 13:08 +0100)
tree02232380bcf1f78ad68f036a6a98282fe03c77c2
parent4240be45632db7831129f124bcf53c1223825b0f
rtl8139: check TCP Data Offset field (CVE-2015-5165)

The TCP Data Offset field contains the length of the header.  Make sure
it is valid and does not exceed the IP data length.

Reported-by: 朱东海(启路) <donghai.zdh@alibaba-inc.com>
Reviewed-by: Jason Wang <jasowang@redhat.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
hw/net/rtl8139.c