From nobody Fri Nov 21 10:18:01 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) client-ip=8.43.85.245; envelope-from=devel-bounces@lists.libvirt.org; helo=lists.libvirt.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass(p=reject dis=none) header.from=lists.libvirt.org ARC-Seal: i=1; a=rsa-sha256; t=1762515516; cv=none; d=zohomail.com; s=zohoarc; b=Wz11vC3SA2xhaaG7FZsIiQXZ1pRunQ0bEPl62rZ3DSzaXvGy64/YwPfGfC7AOhivke1ttbL2R+Ekko3n/TrG5c1sahlWWXiHn+IY7pdHFMliOPf67uhciG5e9LR+E7FXxcFET+2bpdYnIWsST/MAqffG1+GzkAX8LeDBxz/X7t8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1762515516; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Owner:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:References:Subject:Subject:To:To:Message-Id; bh=X1Oe66LmbJg8zvOlxLrhmAccdl7zaa4twgQ2fdYWNmk=; b=TiYESD0rJ8QGW6us/T47rIKANHOy+2bbwbbwAyhLcrpy18+Tw9y6pSH/8zcgy+U4+stmIxijKqAALxob36mgh777ri9roxklP1xQxadCDQoKTEp9Xogcq1C/rv0qgKEqW5+u3/EkgSoev9x+Tnpppilapz04V0zYIl3HKAKN9Vo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=fail; spf=pass (zohomail.com: domain of lists.libvirt.org designates 8.43.85.245 as permitted sender) smtp.mailfrom=devel-bounces@lists.libvirt.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.libvirt.org (lists.libvirt.org [8.43.85.245]) by mx.zohomail.com with SMTPS id 1762515516227820.4947450518347; Fri, 7 Nov 2025 03:38:36 -0800 (PST) Received: by lists.libvirt.org (Postfix, from userid 993) id 88BC74441E; Fri, 7 Nov 2025 06:38:35 -0500 (EST) Received: from [172.19.199.29] (lists.libvirt.org [8.43.85.245]) by lists.libvirt.org (Postfix) with ESMTP id 746AA449EF; Fri, 7 Nov 2025 06:29:58 -0500 (EST) Received: by lists.libvirt.org (Postfix, from userid 993) id 7B205443F0; Fri, 7 Nov 2025 06:29:41 -0500 (EST) Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (3072 bits) server-digest SHA256) (No client certificate requested) by lists.libvirt.org (Postfix) with ESMTPS id 043C541885 for ; Fri, 7 Nov 2025 06:26:46 -0500 (EST) Received: from mail-wr1-f72.google.com (mail-wr1-f72.google.com [209.85.221.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-38-LQ13GDu1M2yi0PWxw07Jfg-1; Fri, 07 Nov 2025 06:26:45 -0500 Received: by mail-wr1-f72.google.com with SMTP id ffacd0b85a97d-4298da9fc21so283257f8f.1 for ; Fri, 07 Nov 2025 03:26:44 -0800 (PST) Received: from wheatley.localdomain ([85.93.96.130]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-42ac6794f63sm4845109f8f.42.2025.11.07.03.26.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 Nov 2025 03:26:42 -0800 (PST) Received: from wheatley.pinto-pinecone.ts.net (wheatley.k8r.cz [127.0.0.1]) by wheatley.localdomain (Postfix) with ESMTP id 05477E161B57; Fri, 07 Nov 2025 12:26:42 +0100 (CET) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on lists.libvirt.org X-Spam-Level: X-Spam-Status: No, score=-5.0 required=5.0 tests=BAYES_00,DKIM_INVALID, DKIM_SIGNED,MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED,RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED,SPF_PASS autolearn=unavailable autolearn_force=no version=4.0.1 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1762514806; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=X1Oe66LmbJg8zvOlxLrhmAccdl7zaa4twgQ2fdYWNmk=; b=J4SXsS9DGlY43uSVSYcTmQNAw+vUgRtT1rEN+N3QfERb1Qg+b0bR6NjKAMOdu87Rmg29hg 4NbZ4DtXnDmgI9ZwBH2Y5dvSw//D68qAfA2Xpm8bfCgT5XPrW3Ffah8+F+m5qpAu5WYp7t ztHRjpoT9wV0AF3MnoXTlYioJ3nfOPw= X-MC-Unique: LQ13GDu1M2yi0PWxw07Jfg-1 X-Mimecast-MFC-AGG-ID: LQ13GDu1M2yi0PWxw07Jfg_1762514804 X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1762514804; x=1763119604; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=X1Oe66LmbJg8zvOlxLrhmAccdl7zaa4twgQ2fdYWNmk=; b=D8Sw9f232AXSIno7T9AL8MQQaqVAVYZF/+CONzIkISFcMd2la60ZP0W/WM5PE7piH3 n0nRTb/wkliPFQYSirjhgupPBTVuR/WE9Uj0P2A2URvAuxntaRuZQhJd0W/s864lqYi2 YnLoUSAqj7YLiqFHc2yMUg5GQ8ogRu5ml0q0Maos1flaEmSAkZRQ1jZcaM0Z/NN53pg5 T21Dm2GE19zEz4mnp7bBm0tnrJ+aTXqX7V+MekKl2w8LGrMN7WHAXVkmaLzCFesVwdrS TDBYRVKmqiqT02o6PhBfNpGQf6bF7zylcOkE0uF0wuoqqMafEog7beAgksG0GYwYUKh9 pkkA== X-Gm-Message-State: AOJu0YzqV1AY4XTjk6gHpm+Sl7Dwa/wk4U0o8sn1EIto5QsH0I5HA15w RZJIyKyqMngDEXG1pleyOW6gnwT43GvHeQjqhHGHgBS+Zyt0YuB5D/mSkbk54/kFXvx7rFFBCLE /VB4bFsi+G0gcniTCgNWAHhrEZTg+/xdr6dGOd1cOWWhk6CLwdDcGyde63xs6APK84oM= X-Gm-Gg: ASbGncv3M54EohxG7v730JGIsbSpW0QzIcm/uzv/cY6qKWNMtztQD7IxJXa2GbeCnVK HHlqVpqi3Q8/5p311Fdtn55Kh6diD6sxIWpvZQ1bAwsKeeagqWWPp1gBQYYgL2ZDIGKwf9jnIU1 KjB7uRe7W5dzPqlJzxBJFDVGfh5PmYAPUnNRViPoKFpasIfyvB9nyz8Z8+knhUu43HiS1Th2AyC BmAkr8UWC0Zm3KAu4F0zgWlnPWvSRWDDg7Kbq3tdmmC+4M9UkTPgDwMHZyg6iTpb9wIr9CwDcbn MAPIx1ptPB0h1tNS9cbLsg2NCqUnKygiveuQspHwy9rYJp4qZWFE2QvcQ+SFmrJQlAShQAiuY3e IQauew4fv X-Received: by 2002:a05:6000:186d:b0:427:665:e373 with SMTP id ffacd0b85a97d-42ae5af418amr2474087f8f.63.1762514803958; Fri, 07 Nov 2025 03:26:43 -0800 (PST) X-Google-Smtp-Source: AGHT+IHTRTq4Jl0xHudQ0aA/Q8E2l3zkas0bXKZifM7eFda5aIiPYa6Nz35vwgtijbdC0YrHiJLPYw== X-Received: by 2002:a05:6000:186d:b0:427:665:e373 with SMTP id ffacd0b85a97d-42ae5af418amr2474066f8f.63.1762514803580; Fri, 07 Nov 2025 03:26:43 -0800 (PST) To: devel@lists.libvirt.org Subject: [PATCH 2/7] bhyve: Check ACLs before parsing the whole domain XML Date: Fri, 7 Nov 2025 12:26:30 +0100 Message-ID: <51ab6413009bd3def7dd06252c7fc9fd78a5930d.1762514681.git.mkletzan@redhat.com> X-Mailer: git-send-email 2.51.2 In-Reply-To: References: MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: gCqcwkYtF0jxvJmglfQ9fpO1RRTJ0Iyr3pzruiX-uv0_1762514804 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-ID-Hash: WLTA6XS6JBGYBWR6PBOC4PJMQMA3K3NQ X-Message-ID-Hash: WLTA6XS6JBGYBWR6PBOC4PJMQMA3K3NQ X-MailFrom: mkletzan@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-devel.lists.libvirt.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: =?UTF-8?q?=D0=A1=D0=B2=D1=8F=D1=82=D0=BE=D1=81=D0=BB=D0=B0=D0=B2=20=D0=A2=D0=B5=D1=80=D0=B5=D1=88=D0=B8=D0=BD?= X-Mailman-Version: 3.3.10 Precedence: list List-Id: Development discussions about the libvirt library & tools Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Martin Kletzander via Devel Reply-To: Martin Kletzander X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZM-MESSAGEID: 1762515517626154100 From: Martin Kletzander Utilise the new virDomainDefIDsParseString() for that. Fixes: CVE-2025-12748 Reported-by: =D0=A1=D0=B2=D1=8F=D1=82=D0=BE=D1=81=D0=BB=D0=B0=D0=B2 =D0=A2= =D0=B5=D1=80=D0=B5=D1=88=D0=B8=D0=BD Signed-off-by: Martin Kletzander --- src/bhyve/bhyve_driver.c | 24 ++++++++++++++++++------ 1 file changed, 18 insertions(+), 6 deletions(-) diff --git a/src/bhyve/bhyve_driver.c b/src/bhyve/bhyve_driver.c index 00a484ae219c..72f1d7ace8e6 100644 --- a/src/bhyve/bhyve_driver.c +++ b/src/bhyve/bhyve_driver.c @@ -486,6 +486,15 @@ bhyveDomainDefineXMLFlags(virConnectPtr conn, const ch= ar *xml, unsigned int flag if (!caps) return NULL; =20 + /* Avoid parsing the whole domain definition for ACL checks */ + if (!(def =3D virDomainDefIDsParseString(xml, provconn->xmlopt, parse_= flags))) + return NULL; + + if (virDomainDefineXMLFlagsEnsureACL(conn, def) < 0) + return NULL; + + g_clear_pointer(&def, g_object_unref); + if ((def =3D virDomainDefParseString(xml, privconn->xmlopt, NULL, parse_flags)) =3D=3D NULL) goto cleanup; @@ -493,9 +502,6 @@ bhyveDomainDefineXMLFlags(virConnectPtr conn, const cha= r *xml, unsigned int flag if (virXMLCheckIllegalChars("name", def->name, "\n") < 0) goto cleanup; =20 - if (virDomainDefineXMLFlagsEnsureACL(conn, def) < 0) - goto cleanup; - if (bhyveDomainAssignAddresses(def, NULL) < 0) goto cleanup; =20 @@ -889,11 +895,17 @@ bhyveDomainCreateXML(virConnectPtr conn, if (flags & VIR_DOMAIN_START_AUTODESTROY) start_flags |=3D VIR_BHYVE_PROCESS_START_AUTODESTROY; =20 - if ((def =3D virDomainDefParseString(xml, privconn->xmlopt, - NULL, parse_flags)) =3D=3D NULL) - goto cleanup; + /* Avoid parsing the whole domain definition for ACL checks */ + if (!(def =3D virDomainDefIDsParseString(xml, provconn->xmlopt, parse_= flags))) + return NULL; =20 if (virDomainCreateXMLEnsureACL(conn, def) < 0) + return NULL; + + g_clear_pointer(&def, g_object_unref); + + if ((def =3D virDomainDefParseString(xml, privconn->xmlopt, + NULL, parse_flags)) =3D=3D NULL) goto cleanup; =20 if (bhyveDomainAssignAddresses(def, NULL) < 0) --=20 2.51.2