@samitouri / QOSamiQemu / commits / 1785bf9685

vfio/pci: Grow buffer in vfio_pci_host_match()

Each field of PCIHostDeviceAddress is an unsigned int, therefore while a valid address is limited to 13 characters, an invalid address could exceed the specified format, up to: ffffffff:ffffffff:ffffffff.ffffffff<NUL> This requires 36 characters with the terminator. Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp> Reviewed-by: Alex Williamson <alex.williamson@nvidia.com> Message-ID: <20260305-nvme-v4-2-b65b9de1839f@rsg.ci.i.u-tokyo.ac.jp> Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>

Akihiko Odaki committed Mar 5, 2026 at 15:16 UTC 1785bf9685ecb424d0f80a4472aa0c623a07a88c
1 file changed +1 -1
hw/vfio/pci.c
+1 -1
@@ -2739,7 +2739,7 @@ void vfio_pci_post_reset(VFIOPCIDevice *vdev)
2739
2740 bool vfio_pci_host_match(PCIHostDeviceAddress *addr, const char *name)
2741 {
2742 - char tmp[13];
2742 + char tmp[36];
2743
2744 sprintf(tmp, "%04x:%02x:%02x.%1x", addr->domain,
2745 addr->bus, addr->slot, addr->function);