vfio/pci: Grow buffer in vfio_pci_host_match()
Each field of PCIHostDeviceAddress is an unsigned int, therefore while a valid address is limited to 13 characters, an invalid address could exceed the specified format, up to: ffffffff:ffffffff:ffffffff.ffffffff<NUL> This requires 36 characters with the terminator. Signed-off-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp> Reviewed-by: Alex Williamson <alex.williamson@nvidia.com> Message-ID: <20260305-nvme-v4-2-b65b9de1839f@rsg.ci.i.u-tokyo.ac.jp> Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Akihiko Odaki committed
Mar 5, 2026 at 15:16 UTC
1785bf9685ecb424d0f80a4472aa0c623a07a88c
1 file changed
+1
-1
hw/vfio/pci.c
+1
-1
@@ -2739,7 +2739,7 @@ void vfio_pci_post_reset(VFIOPCIDevice *vdev)
2739
2740
bool vfio_pci_host_match(PCIHostDeviceAddress *addr, const char *name)
2741
{
2742
- char tmp[13];
2742
+ char tmp[36];
2743
2744
sprintf(tmp, "%04x:%02x:%02x.%1x", addr->domain,
2745
addr->bus, addr->slot, addr->function);