From nobody Sat Sep 26 21:37:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=swemel.ru ARC-Seal: i=1; a=rsa-sha256; t=1789489118; cv=none; d=zohomail.com; s=zohoarc; b=ZHp3UWNRv4IBxeU0N/nhh5fXQ1xTz/rBVU79ORryLbdaLNaqM9hs4l8dLpzFwfIys147lWkF1tE55ahAG/fbBnytVSs8ij5vdqTJLU6BCU0BMcE925JGjftNryYyp7HWKIV+7RmRYUuXDSJ3t1DdcxOkzAX3dR8nfyxORWxblhw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789489118; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=2DjEtRCtdauQXNDedT+2xLAS27KLrQEkzuO1dLWhZaQ=; b=CXOu/UqaOpT4Xetb0nAnspicqY0xZXMa77gx8kanvZ/D+TDt2oL1mKrjWvVlLjeGOmliI+aWWdlUPVcdcZA0irPxVEYcEsmv8y5AFqgXHsowoTPDTVq0hhyUCYY2nEWM1EhUCfP+rfFnD5tujvNclnoKIhZgABJgq4dOlwUo6rI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789489117274647.4250662201351; Tue, 15 Sep 2026 09:18:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6Vqp-0003FX-BW; Tue, 15 Sep 2026 12:17:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6Vqg-0003FB-Fo for qemu-devel@nongnu.org; Tue, 15 Sep 2026 12:17:35 -0400 Received: from mx.swemel.ru ([95.143.211.150]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6Vqe-0007O7-7t for qemu-devel@nongnu.org; Tue, 15 Sep 2026 12:17:34 -0400 Message-ID: <13ad0871-44dd-40eb-aad1-d08cc2d7dfe5@swemel.ru> DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=swemel.ru; s=mail; t=1789489048; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=2DjEtRCtdauQXNDedT+2xLAS27KLrQEkzuO1dLWhZaQ=; b=HaovFGlm2/JNgp/vCao6aLB+yUx74xJLAeNteqAGwHgCjo8uNxE9GQOAa3I5uXB8AZ7P8/ XuiQ1n++kb35clGnMox0N5FinEY6kapY3b0YFr5unXht2D/i9Dr10ReSkaz+2H+aONMLFP /N7di+oC1UAT5AHYCqSMn+MnsQ1yBNM= Date: Tue, 15 Sep 2026 19:17:28 +0300 MIME-Version: 1.0 Content-Language: en-US, ru-RU To: qemu-devel@nongnu.org Cc: thuth@redhat.com, mst@redhat.com, stefanha@redhat.com, kwolf@redhat.com From: =?UTF-8?B?0J3QuNC60L7Qu9Cw0Lkg0JfQvtGA0LjQvQ==?= Subject: PATCH] hw/s390x/s390-hypercall: fix potential NULL dereference in handle_virtio_ccw_notify Content-Type: text/plain; charset="utf-8"; format="flowed" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=95.143.211.150; envelope-from=zorin@swemel.ru; helo=mx.swemel.ru X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @swemel.ru) X-ZM-MESSAGEID: 1789489124948158500 SWSA#4992cdf0-415c-45c1-be1a-71213467347d The `virtio_ccw_get_vdev()` function can return a `NULL` pointer if the corresponding subchannel driver data (`sch->driver_data`) is not initialized or has been cleared. If `vdev` is `NULL`, passing it directly into=20 `virtio_queue_get_num(vdev, vq_idx)` results in a `NULL` pointer dereference, which can lead to a hypervisor crash or unexpected termination of the QEMU process. Fix this by adding an explicit check for `!vdev` before verifying the queue index and its capacity, returning `-EINVAL` early if the device is missing or not bound to the subchannel. Signed-off-by: Nikolay N Zorin --- =C2=A0hw/s390x/s390-hypercall.c | 2 +- =C2=A01 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/s390x/s390-hypercall.c b/hw/s390x/s390-hypercall.c index ac1b08b2..fd2972c0 100644 --- a/hw/s390x/s390-hypercall.c +++ b/hw/s390x/s390-hypercall.c @@ -44,7 +44,7 @@ static int handle_virtio_ccw_notify(uint64_t subch_id,=20 uint64_t data) =C2=A0 =C2=A0 =C2=A0} =C2=A0 =C2=A0 =C2=A0vdev =3D virtio_ccw_get_vdev(sch); -=C2=A0 =C2=A0 if (vq_idx >=3D VIRTIO_QUEUE_MAX || !virtio_queue_get_num(vd= ev,=20 vq_idx)) { +=C2=A0 =C2=A0 if (!vdev || vq_idx >=3D VIRTIO_QUEUE_MAX ||=20 !virtio_queue_get_num(vdev, vq_idx)) { =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0return -EINVAL; =C2=A0 =C2=A0 =C2=A0} --=20 2.43.0