From nobody Fri Nov 21 10:19:31 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) client-ip=8.43.85.245; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1762515308; cv=none; d=zohomail.com; s=zohoarc; b=GKHKlxSm34LmLiF2O+5Jk/8Lztc/mTUFc63vdS7COkfHJLyR0fY8eNTFrSHNeCNh6xGoxVYGBFivG8D4vBqG8jJW4FqiEhMlY606XnmMqX4iYtyFwa/rHX8nKz51e0SGka3SnjbJScpCYZsBWYZ1SvakfAiPvaiegE+a04YD+Rg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1762515308; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:References:Subject:Subject:To:To:Message-Id; bh=t4FlW1KJuxUpXCJUOmcexjwA2Z5DarW3z0716MkS7NY=; b=FxKFCyifhdkHhTgmDwaD3AhxoS8NRjUl5iHHW2JioigUAF+t7oJGN0XYwowNG3o56CO4aGKrFHRDb3it27ikYwLMwtvVQGaGVmltUkrC4PPSmSXe9MMYrdQNPPT6bRGCFXhcxp4x06mt/85xuKHY22egqC7LTxhr3zPyWEq397A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [8.43.85.245]) by mx.zohomail.com with SMTPS id 1762515308548761.5569557637306; Fri, 7 Nov 2025 03:35:08 -0800 (PST) Received: by lists.libvirt.org (Postfix, from userid 993) id 9E30B41B11; Fri, 7 Nov 2025 06:35:07 -0500 (EST) Received: from [172.19.199.29] (lists.libvirt.org [8.43.85.245]) by lists.libvirt.org (Postfix) with ESMTP id 0C2F64444E; Fri, 7 Nov 2025 06:29:32 -0500 (EST) Received: by lists.libvirt.org (Postfix, from userid 993) id E1B0A443EC; Fri, 7 Nov 2025 06:29:23 -0500 (EST) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits)) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 4C2E84462C for ; Fri, 7 Nov 2025 06:26:46 -0500 (EST) Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-33-rlJcoTdDMDuu7cgUa8TEVg-1; Fri, 07 Nov 2025 06:26:44 -0500 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-47740c1442dso4709845e9.1 for ; Fri, 07 Nov 2025 03:26:44 -0800 (PST) Received: from wheatley.localdomain ([85.93.96.130]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-47763e4f13dsm38244145e9.5.2025.11.07.03.26.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 Nov 2025 03:26:42 -0800 (PST) Received: from wheatley.pinto-pinecone.ts.net (wheatley.k8r.cz [127.0.0.1]) by wheatley.localdomain (Postfix) with ESMTP id 11B40E161B58; Fri, 07 Nov 2025 12:26:42 +0100 (CET) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-5.0 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED,SPF_PASS autolearn=unavailable autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1762514806; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=t4FlW1KJuxUpXCJUOmcexjwA2Z5DarW3z0716MkS7NY=; b=duzZQM+wTsU0aDGf+qGEka0dXW9uWN0sm9kdU2K8N/rP0Eo35nUE/dfYHTsm2IwwsB+BVE 76u+422URzIUj+fk3Lb1rnZ4QczzFgtbbAKpFALzMQ71097ND/p2SNL++cICupylK421dU ftrAiE8rjr4VaqkkUOXlpgwRtRcSfs4= X-MC-Unique: rlJcoTdDMDuu7cgUa8TEVg-1 X-Mimecast-MFC-AGG-ID: rlJcoTdDMDuu7cgUa8TEVg_1762514804 X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1762514804; x=1763119604; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=t4FlW1KJuxUpXCJUOmcexjwA2Z5DarW3z0716MkS7NY=; b=g2roZBgtZex6EG8R0C4sOpLBYZmLGxgYkvmVEymUcY8Q55/IMSq+0lsrTgML+idD54 q941JuFpROT7X8Ijn8uvAW+IvU1xzq/OHDRdbgHobr0aiUYF1FRL/2gRhdaa9HLOH560 NaJ7ixYyUgnMpGdZlMbcdKrLPK3qVcBlnITn7S1LbmjyrLbr4xqIEfjVOKcOvYqosuth Lt+AZJY1/1XMe5o1czjLJAtP/b7Xe9PFyEdWsB1Ix3isjYcE45HwoInKWSG3uC9QVFIP w3dX4yrdy/e/XXg33zsYhYqf/iYKrswYFa1tQXMZ4sNDel867G9nus+grKFmE5a1/5Ks yaUg== X-Gm-Message-State: AOJu0Yw28RbV7QXHyA4T+zWDpYYQ+2g3oGrJ60DV+P9d9kiBqJ0jXkrw Wb5Ww3plNYwl1DoFLZWPcZG5KcZVfoTJjKxFaW69ohj5XXpbM5z1/Pp49S2eWHdTgEp2Jp1aXEZ TTWnjpB3KTLPaCRw1D9l8h+GhQbRn7QHFSpOsd6RVC26/VJfX3lxX2Esz7UA0yEDBP98= X-Gm-Gg: ASbGncvy8CSSfHOidAxdu58z0UKZT/mJ1dYU9S8SoWYUt+pwohR+WTxKp8av+AMTKYF wDXe3cEZ4ECB4hIzKpfAu/oOECqAgbpn1DCTXHss9f4H5zGi46EkUcXD/mwP9ps1Hjq6wXSZv3q tUns6DDXpQOck4kTkVc6KYIC3GvSO1v8sLD7p2Y/1I6URpJxSiTJd5sL+FX54AxgnNFw5h7kmE0 IY4R8LIwAbvl+lYU4J0oLnsml88yEu4Sl/PcnedAkRsFfCrXjJYXSNy8cz5Au9V4VzvJ9x89rCc RlaK1kCWLMUx+rVdtZ2R+yU0r9FOUhd3t2xF7DdKlz9p66g+IbVIHb9z1UK0XGwe0s9fjrFugOp SNkvslVhs X-Received: by 2002:a05:600c:3146:b0:477:6ae9:87d with SMTP id 5b1f17b1804b1-4776bc9f90dmr26992995e9.4.1762514803666; Fri, 07 Nov 2025 03:26:43 -0800 (PST) X-Google-Smtp-Source: AGHT+IG2Ze2/I7oJxmiyDbvzVNfcvqQXr2yN8d25SNc0RBeiCIPzp1gXGMPXOqAF45X7h6nhyLQIAQ== X-Received: by 2002:a05:600c:3146:b0:477:6ae9:87d with SMTP id 5b1f17b1804b1-4776bc9f90dmr26992585e9.4.1762514803270; Fri, 07 Nov 2025 03:26:43 -0800 (PST) To: devel@lists.libvirt.org Subject: [PATCH 3/7] libxl: Check ACLs before parsing the whole domain XML Date: Fri, 7 Nov 2025 12:26:31 +0100 Message-ID: <46d09e1bdf5891beadbe30b7cc6763cbef4e2c6d.1762514681.git.mkletzan@redhat.com> X-Mailer: git-send-email 2.51.2 In-Reply-To: References: MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: CJvyypRVIF1sRlGlYbM8SceFrzK8djZ1PwsJ1MP5T5w_1762514804 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-ID-Hash: NG3V6NOGH47HP2RY7KF2P4M3QDGVVWZV X-Message-ID-Hash: NG3V6NOGH47HP2RY7KF2P4M3QDGVVWZV X-MailFrom: mkletzan@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: =?UTF-8?q?=D0=A1=D0=B2=D1=8F=D1=82=D0=BE=D1=81=D0=BB=D0=B0=D0=B2=20=D0=A2=D0=B5=D1=80=D0=B5=D1=88=D0=B8=D0=BD?= X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Martin Kletzander via Devel Reply-To: Martin Kletzander X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1762515309176158500 From: Martin Kletzander Utilise the new virDomainDefIDsParseString() for that. Fixes: CVE-2025-12748 Reported-by: =D0=A1=D0=B2=D1=8F=D1=82=D0=BE=D1=81=D0=BB=D0=B0=D0=B2 =D0=A2= =D0=B5=D1=80=D0=B5=D1=88=D0=B8=D0=BD Signed-off-by: Martin Kletzander --- src/libxl/libxl_driver.c | 20 +++++++++++++++----- 1 file changed, 15 insertions(+), 5 deletions(-) diff --git a/src/libxl/libxl_driver.c b/src/libxl/libxl_driver.c index 107477250ab8..0cdeec08bedc 100644 --- a/src/libxl/libxl_driver.c +++ b/src/libxl/libxl_driver.c @@ -1027,13 +1027,18 @@ libxlDomainCreateXML(virConnectPtr conn, const char= *xml, if (flags & VIR_DOMAIN_START_VALIDATE) parse_flags |=3D VIR_DOMAIN_DEF_PARSE_VALIDATE_SCHEMA; =20 - if (!(def =3D virDomainDefParseString(xml, driver->xmlopt, - NULL, parse_flags))) + if (!(def =3D virDomainDefIDsParseString(xml, driver->xmlopt, parse_fl= ags))) goto cleanup; =20 if (virDomainCreateXMLEnsureACL(conn, def) < 0) goto cleanup; =20 + g_clear_pointer(&def, virObjectUnref); + + if (!(def =3D virDomainDefParseString(xml, driver->xmlopt, + NULL, parse_flags))) + goto cleanup; + if (!(vm =3D virDomainObjListAdd(driver->domains, &def, driver->xmlopt, VIR_DOMAIN_OBJ_LIST_ADD_LIVE | @@ -2813,6 +2818,14 @@ libxlDomainDefineXMLFlags(virConnectPtr conn, const = char *xml, unsigned int flag if (flags & VIR_DOMAIN_DEFINE_VALIDATE) parse_flags |=3D VIR_DOMAIN_DEF_PARSE_VALIDATE_SCHEMA; =20 + if (!(def =3D virDomainDefIDsParseString(xml, driver->xmlopt, parse_fl= ags))) + goto cleanup; + + if (virDomainDefineXMLFlagsEnsureACL(conn, def) < 0) + goto cleanup; + + g_clear_pointer(&def, virObjectUnref); + if (!(def =3D virDomainDefParseString(xml, driver->xmlopt, NULL, parse_flags))) goto cleanup; @@ -2820,9 +2833,6 @@ libxlDomainDefineXMLFlags(virConnectPtr conn, const c= har *xml, unsigned int flag if (virXMLCheckIllegalChars("name", def->name, "\n") < 0) goto cleanup; =20 - if (virDomainDefineXMLFlagsEnsureACL(conn, def) < 0) - goto cleanup; - if (!(vm =3D virDomainObjListAdd(driver->domains, &def, driver->xmlopt, 0, --=20 2.51.2