From nobody Mon Aug 24 09:07:50 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) client-ip=38.145.34.151; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1786547512; cv=none; d=zohomail.com; s=zohoarc; b=UndgRrpKi+HujTeaKAmECyocJwBrQEp1b9vE2xt2PBdhYgiRThPab20vbUy+AlEqlguIxgbAWoC2/je/+hggmt1Vpd0UxPy1XXT1H7n0UyJeQ+vZFRBqYqxITFuxkRRvIrmsQmIelMSo3Ym6gLJi9i+PYjLbPjVp9AoXzKtv9nQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547512; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:Subject:Subject:To:To:Message-Id:Cc; bh=zS1e6TfhhJ8BnFC3pEDAmQvWch77HOkrsX4GxATAWsg=; b=lrU14Z8BsxcCrCISgP3AyOeHo0LQhCyFR1GnTlVl9wJOvzbFTRdxuykSkHkPeci6da/rrySvu2vWwtFxtoGwqOIFE4I3Pntfc05cmco2BTmnu/II34N0eJLgL2irh/jchA297YdlcXmK3/nNVyeNQ3B+ExGBVDCARj4FQXE1RBM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 38.145.34.151 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [38.145.34.151]) by mx.zohomail.com with SMTPS id 1786547512223727.2489906958322; Wed, 12 Aug 2026 08:11:52 -0700 (PDT) Received: by lists.libvirt.org (Postfix, from userid 993) id 97CED418E6; Wed, 12 Aug 2026 11:11:50 -0400 (EDT) Received: from [172.19.199.10] (unknown [10.16.107.18]) by lists.libvirt.org (Postfix) with ESMTP id E01D641A23; Wed, 12 Aug 2026 11:10:36 -0400 (EDT) Received: by lists.libvirt.org (Postfix, from userid 993) id D5BD74183E; Wed, 12 Aug 2026 11:10:28 -0400 (EDT) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 61CEB3F375 for ; Wed, 12 Aug 2026 11:10:27 -0400 (EDT) Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-170-ejpGB1StMsS8HQez-UO0Yw-1; Wed, 12 Aug 2026 11:10:20 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5C5E31800742 for ; Wed, 12 Aug 2026 15:10:19 +0000 (UTC) Received: from speedmetal.openshiftapps.com (unknown [10.44.22.5]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 97B4F3001DAF for ; Wed, 12 Aug 2026 15:10:18 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-2.7 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL,SPF_HELO_PASS autolearn=unavailable autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547426; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=zS1e6TfhhJ8BnFC3pEDAmQvWch77HOkrsX4GxATAWsg=; b=MD5X03JtktsNDFQljiCT3KIqFPIpBOLT0d+YeNI38TbXFXJVweje3RisvXzXyfFaaej6ov Br6Yv2PJZCbmu+mXOysX6vwbkjHh6oUu3bLQzx+w9qKXboUhPC5TDAYpwTVozq5PgzHj2N ipHwEuvpzJlWmkBsROMO+s06/7FrVXo= X-MC-Unique: ejpGB1StMsS8HQez-UO0Yw-1 X-Mimecast-MFC-AGG-ID: ejpGB1StMsS8HQez-UO0Yw_1786547419 To: devel@lists.libvirt.org Subject: [PATCH] remote: Fix integer overflow in RPC handler for virNodeGetFreePages (CVE-2026-18917) Date: Wed, 12 Aug 2026 17:10:17 +0200 Message-ID: <29aea17faa34a3cb6ccb0739d5d95d69b7e1a809.1786547417.git.pkrempa@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: E7VaPIO9NWuv7zUm-lByfbjp0CXg58y6f79V6y9i-PU_1786547419 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: quoted-printable Message-ID-Hash: DRFW25BFL2U5VBDFEIRS46SUWCUJ65MY X-Message-ID-Hash: DRFW25BFL2U5VBDFEIRS46SUWCUJ65MY X-MailFrom: pkrempa@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Peter Krempa via Devel Reply-To: Peter Krempa X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1786547516181158501 Content-Type: text/plain; charset="utf-8" From: Peter Krempa CVE-2026-18917 The RPC handler 'remoteDispatchNodeGetFreePages' multiplies the 'npages' argument with the 'cellcount' argument passed to 'virNodeGetFreePages', both of which are declared as 'unsigned int' to both do an RPC limit check against the 'REMOTE_NODE_MAX_CELLS' constant and then to allocate the memory to hold the result from the actual hypervisor driver. Since both the values are 'unsigned int' the product is also unsigned int so big enough numbers can overflow, both passing the check and also allocating not enough memory for the result. The hypervisor driver assumes that the passed buffer is large enough and overwrites memory. When this happens the the hypervisor daemon crashes. This can be triggered e.g. by passing 1023 and 4198405 as values which multiply to 1019 after wrapping to 32 bit unsigned value. Use the VIR_INT_MULTIPLY_OVERFLOW macro in the check to avoid the issue the same way as we do for other APIs doing multiplication of arguments to determine amount of required memory. Fixes: 34f2d0319d2098c77c8cc27d8350616029125a2b (v1.2.5-164-g34f2d0319d) Closes: https://gitlab.com/libvirt/libvirt/-/work_items/903 Signed-off-by: Peter Krempa Reviewed-by: Daniel P. Berrang=C3=A9 --- src/remote/remote_daemon_dispatch.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/src/remote/remote_daemon_dispatch.c b/src/remote/remote_daemon= _dispatch.c index 95ab173b7c..e548438250 100644 --- a/src/remote/remote_daemon_dispatch.c +++ b/src/remote/remote_daemon_dispatch.c @@ -6752,13 +6752,14 @@ remoteDispatchNodeGetFreePages(virNetServer *server= G_GNUC_UNUSED, if (!conn) goto cleanup; - if (args->pages.pages_len * args->cellCount > REMOTE_NODE_MAX_CELLS) { - virReportError(VIR_ERR_INTERNAL_ERROR, "%s", - _("the result won't fit into REMOTE_NODE_MAX_CELLS"= )); + if (VIR_INT_MULTIPLY_OVERFLOW(args->pages.pages_len, args->cellCount) = || + args->pages.pages_len * args->cellCount > REMOTE_NODE_MAX_CELLS) { + virReportError(VIR_ERR_INTERNAL_ERROR, + _("npages * cellcount > REMOTE_NODE_MAX_CELLS (%1$u= )"), + REMOTE_NODE_MAX_CELLS); goto cleanup; } - /* Allocate return buffer. */ ret->counts.counts_val =3D g_new0(uint64_t, args->pages.pages_len * args->cellCoun= t); --=20 2.55.0