cpu_ioreq_pio, cpu_ioreq_move: i should be uint32_t rather than int The current code compare i (int) with req->count (uint32_t) in a for loop, risking an infinite loop if req->count is equal to UINT_MAX. Also i is only used in comparisons or multiplications with unsigned integers. Signed-off-by: Stefano Stabellini <[email protected]> Cc: Dongxiao Xu <[email protected]> Cc: Stefano Stabellini <[email protected]> Signed-off-by: Ian Jackson <[email protected]>
diff --git a/xen-all.c b/xen-all.c index ef430ca..daf43b9 100644 --- a/xen-all.c +++ b/xen-all.c
@@ -721,7 +721,7 @@ static void cpu_ioreq_pio(ioreq_t *req) { - int i; + uint32_t i; if (req->dir == IOREQ_READ) { if (!req->data_is_ptr) { @@ -750,7 +750,7 @@ static void cpu_ioreq_move(ioreq_t *req) { - int i; + uint32_t i; if (!req->data_is_ptr) { if (req->dir == IOREQ_READ) {