ati-vga: Do not access pixel outside the screen
We check end of screen before writing the pixel but before that complement color also accesses screen pixel so we have to check before that. This fixes a segmentation fault with guest_hwcursor when pointer is partially out of screen at lower right corner. Signed-off-by: BALATON Zoltan <balaton@eik.bme.hu> Reviewed-by: Chad Jablonski <chad@jablonski.xyz> Message-ID: <26db0715a6b9f6504f394010513facc9a37882ad.1773009887.git.balaton@eik.bme.hu> Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
BALATON Zoltan committed
Mar 8, 2026 at 23:49 UTC
e9fa0330a20d117d70f604cb5a1fd647f531c1b7
1 file changed
+3
-3
hw/display/ati.c
+3
-3
@@ -214,6 +214,9 @@ static void ati_cursor_draw_line(VGACommonState *vga, uint8_t *d, int scr_y)
214
uint8_t abits = vga_read_byte(vga, srcoff + i);
215
uint8_t xbits = vga_read_byte(vga, srcoff + i + 8);
216
for (j = 0; j < 8; j++, abits <<= 1, xbits <<= 1, idx++) {
217
+ if (vga->hw_cursor_x + idx >= h) {
218
+ return; /* end of screen, don't span to next line */
219
+ }
220
if (abits & BIT(7)) {
221
if (xbits & BIT(7)) {
222
color = dp[idx] ^ 0xffffffff; /* complement */
@@ -224,9 +227,6 @@ static void ati_cursor_draw_line(VGACommonState *vga, uint8_t *d, int scr_y)
227
color = (xbits & BIT(7) ? s->regs.cur_color1 :
228
s->regs.cur_color0) | 0xff000000;
229
}
227
- if (vga->hw_cursor_x + idx >= h) {
228
- return; /* end of screen, don't span to next line */
229
- }
230
dp[idx] = color;
231
}
232
}