From nobody Tue Apr 21 14:38:43 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1776661707; cv=none; d=zohomail.com; s=zohoarc; b=lSdXcuypcVk83a2ZH8R2AyQtRXFjYrxDf6BMTReR8n0m923/JN4hSxzQ2SV7nSOCl0k3Ts+qdroeoA39tVWOLsqZa5uZG6qJ9Wzil8dCKUxk0UYlLT4TLq1ylKCUh6yzZI9zTA9l/YMgVL/Rp/4+e/7iV0/8BRrY1RPX5RthN58= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1776661707; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=L4L7y6C8teQb1pIcSjZXj7EqDslM7XaqTZ3gXfLwQzU=; b=dLw+CtubnnkI+/qmDkUigEY8+7zkULPAHksFbAyFbW6LknNvPxtGVNbPr6ZA78QEUw1s5KcFPKNmQ9nFkTgs5wpDojtzxzeAHTzzlm5Xn4/jSMPYBMZbd1ysfaOQ7rXXfWayXJgiBjpfn+CXAkqH0JIH0xxZYsBE1yM6vXv5yq0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1776661707805364.20586794858207; Sun, 19 Apr 2026 22:08:27 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wEgqw-0004rc-7K; Mon, 20 Apr 2026 01:07:22 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wEgqu-0004qV-8l for qemu-devel@nongnu.org; Mon, 20 Apr 2026 01:07:20 -0400 Received: from mail-wr1-x434.google.com ([2a00:1450:4864:20::434]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wEgqr-0002av-Eg for qemu-devel@nongnu.org; Mon, 20 Apr 2026 01:07:19 -0400 Received: by mail-wr1-x434.google.com with SMTP id ffacd0b85a97d-43d77f6092eso1706840f8f.2 for ; Sun, 19 Apr 2026 22:07:13 -0700 (PDT) Received: from [127.0.1.1] (athedsl-4440559.home.otenet.gr. [79.129.177.223]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43fe4e3a341sm28886954f8f.24.2026.04.19.22.07.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Apr 2026 22:07:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1776661632; x=1777266432; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=L4L7y6C8teQb1pIcSjZXj7EqDslM7XaqTZ3gXfLwQzU=; b=M4Ns0dU9X1TbftFbZamnsLWv6UFZWGXKk+TcxiGkYGcKEJ4Oh5elq9ouqP+E3caGDy 4kWWZHaz/fl00h1ahFPb5bmgdHowsaIEolMRoimWmNkbUB1wtW8RdHmNqSToVRa+Q3N4 MvktqHUoe4SB9qRax2VP7WK1JT2A4DSD7qBHmlUoOTBMWWD+g0CLhgjhdkIEs+Z1JRyV XeUb3rUbCLblZAq10SOco5IWqpHwmuNoraWXB/IoiZw9gzKizmYCmJtnPhKLocbFMag4 kxPL9UX2lPts2T6TO247NW31cXRAcAfr4EvY7e++CuiqJXf7ypIRqVD001kNr9G1d+CP 9/2Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776661632; x=1777266432; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=L4L7y6C8teQb1pIcSjZXj7EqDslM7XaqTZ3gXfLwQzU=; b=AAEwQN1DBFaYSLZmo/NtT8XD2R//ggkRzg69d9LBdDrfZqcPlfq+6W/GKaEPrk68oy qqQmeE9rWHu6dSDVFgdQUT9iX65NPqO9CzliTvyksSj/1vZ6WP6gcMqc10rqoteoRPkK wFWdz39Etl8wEi1mrKpQl97wHLno2YHNHtO4drSqewMjJItHyaViCR2X4EZgzghnPNZF 3944ydbhOMTikPW9vKO0UwkE6UgeyX+SKHqs1q+fjcrGCzNR6e4s8uQu9GJ4/qekTjLM GUl6SwrkPcRKBAGwSb6hihSdpkBaIqx0HCci6hgUzK57F1qIns627+1SKkgZF6LMsRLJ C3DA== X-Gm-Message-State: AOJu0Yxs5iQhyahX4S8I++b2o42pIMD79gl/W77q4gntMnN6rTIRvTln d7jvRqEUE9uACRXXfCURR5yxCf9VIupeJcJ2hxnE+WYkivY6upbOWjd8/Iow53UIKhh8po9w3CV Ac+EOwfQ= X-Gm-Gg: AeBDievyd1gudUw8+NUP67S8L/GlSKJ215gkvn3asEk7Iub26ktiqTKSJgs2MrneVDK XdQ5eHRTBuvLyYAd5bl/f9OJPQ1kqFo0/VxREQdBL+SlOxoILKTBJoENoMDB0kF1uy0xKqmlzzo Hv38LIKymi+ZZn/2SGvGFkm/i0ReAR84U+tMMrbOhmNV/xCi2ivtzfs6tEYHuI7MUWTvrTM7yr3 Va/XTFBh1btVir+wljfYcGmpCYGa3gIkwwz62MiVL+yENs10M/SwZj46P+wrrlpKScG9k/RwV4j wokIpEFxQpOBlh+ZXHC1Znmm6AgB3zS0BysyUYfx//juy0RqigfxqkJ+hQy+tvsX43VkC6irbsi QsK3z6o6jtIp3lOHjn719ORXjiZPHBYnomtiXrluwLp7ipEcGBBTi8iON0+nyfs+6UgGF8ZSGwq W+C9KjBr8PvC8RKJCHZh+viwsgg/4YG+eM/7U/iOEbyaOkg3OALSdrYIOdmmfgesKLE47nYkB+1 XxUFSSS4QpEiHHYqC1yLNLOMaG1j0zP2O5+HcqSuC1GiBbKUIs= X-Received: by 2002:a05:6000:2307:b0:43b:3e40:2223 with SMTP id ffacd0b85a97d-43fe3dcc52cmr18293730f8f.19.1776661630925; Sun, 19 Apr 2026 22:07:10 -0700 (PDT) From: Manos Pitsidianakis Date: Mon, 20 Apr 2026 08:07:05 +0300 Subject: [PATCH v3 1/2] virtio-snd: check rx buffer descriptor size MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260420-virtio-fixups-v3-1-07aef1eff9d2@linaro.org> References: <20260420-virtio-fixups-v3-0-07aef1eff9d2@linaro.org> In-Reply-To: <20260420-virtio-fixups-v3-0-07aef1eff9d2@linaro.org> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , "Michael S. Tsirkin" , =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= , =?utf-8?q?Alex_Benn=C3=A9e?= , Richard Henderson , qemu-stable@nongnu.org, Manos Pitsidianakis X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=1448; i=manos.pitsidianakis@linaro.org; h=from:subject:message-id; bh=0XTx6kbq4YY1BBPqSAfMX1GSupccz3LwWPrnsQLDA7E=; b=LS0tLS1CRUdJTiBQR1AgTUVTU0FHRS0tLS0tCgpvd0VCYlFLUy9aQU5Bd0FLQVhjcHgzQi9mZ 25RQWNzbVlnQnA1YlI4TU83V0ZtRzZFaTlpMzBhQTBESjA4RW8yCnNpcGQxcHpzenA5dDgwVnhE ckdKQWpNRUFBRUtBQjBXSVFUTVhCdE9SS0JXODRkd0hSQjNLY2R3ZjM0SjBBVUMKYWVXMGZBQUt DUkIzS2Nkd2YzNEowSkZwRC8wYzJxM2xkTlY4Q3J1VVpYWUhNd3dwNjNtREdKckdheitVdm1BUw pXRDZoYmpnWGtaV2FEb1RoaUZIMWpGRitFUHRlK2xJOUg2MU1WeC9OblYxaERCQzVEbko4WElrK zYzZ2FwQXFPCkFyVlZDbm9MbDZxTVZRbVB5dHJweHRXSk4zalNXZVh5ZjdyWjNKZFNHYVV5MU1R MzFBSnBvQUZyUmdleXlQMXAKMVdZZk9sVFZMMnZ0ek5xeWZkWEVOMHRQd0ppVC9GK1ZHK1lHTWR PZTl1NHd3VHdFbnlaVVpoT1B6OVlRZmNGSgpXcVJwanBWSk0vZlRicVRNQzBEeUZWVnhTNHBFa2 xVRTFzM3JobDdmZGVYT2g5cWV4VVlSOCtpNys3MnhVTG9CCmY3VS9XdTgxUmVJZ0VJMzhLYnpvW DNadzhrQ2paRTVsTHBTczJoQjR2T3R1ZFBnQ2JDc0ZvV1VXb1FpZTRHOVYKTFN3dmZhai9Sc3NJ M2c1L1BtTUN5SGRaaE1rYlJ0TW02WUxOdElHNUJ1VDE1MDNwUGtGRFNKdUQwenhIUTdqSwpwNW9 MZmtRZXVucUM0UlcybHAyMFpuVlYwZ3EyanYvUllld1dSNVAvdndBTWtRZnU0OHRYNWZoY0F4RX hyZ2wvClRUZklRYm0zMzJSZ0JwVWRsN2VpT0srSXdGazM3T21tRk1meXgxR3NEMzFnNkJrTk42M 2NSQ1pGUmNocU9vNkEKaUV1clhEMVFzeTVFVHpiUGJ5WG5RQVNHSVQ1NmIvdUkyNnFxS0J6eHNH ZXlUdTZUdFl6Z1JmejdmbVlJOXl4KwpqRDJQWGMwUkRadzQwbkRxQlZZNWRacXl3RXFyRXB6UWI 2aEI4eG9ONldvcG94aDh3UEFaZEErTHBweVc5NTFOCm5lVVFnQT09Cj1odmtMCi0tLS0tRU5EIF BHUCBNRVNTQUdFLS0tLS0K X-Developer-Key: i=manos.pitsidianakis@linaro.org; a=openpgp; fpr=7C721DF9DB3CC7182311C0BF68BC211D47B421E1 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::434; envelope-from=manos.pitsidianakis@linaro.org; helo=mail-wr1-x434.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1776661710965158500 It must be at least sizeof(virtio_snd_pcm_status). I haven't verified if it's possible to get an underflow, but coverity points it out in CID 1547527 so add a check. Reviewed-by: Alex Benn=C3=A9e Signed-off-by: Manos Pitsidianakis --- hw/audio/virtio-snd.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/hw/audio/virtio-snd.c b/hw/audio/virtio-snd.c index fb5cff386606d03e5cfce88f79e404e510bbcde7..93fbcfb43f7fdcfd5c164b49601= 5da743822f5eb 100644 --- a/hw/audio/virtio-snd.c +++ b/hw/audio/virtio-snd.c @@ -970,12 +970,14 @@ static void virtio_snd_handle_rx_xfer(VirtIODevice *v= dev, VirtQueue *vq) } =20 stream =3D vsnd->pcm.streams[stream_id]; - if (stream =3D=3D NULL || stream->info.direction !=3D VIRTIO_SND_D= _INPUT) { + size =3D iov_size(elem->in_sg, elem->in_num); + if (stream =3D=3D NULL + || stream->info.direction !=3D VIRTIO_SND_D_INPUT + || size < sizeof(virtio_snd_pcm_status)) { goto rx_err; } + size -=3D sizeof(virtio_snd_pcm_status); WITH_QEMU_LOCK_GUARD(&stream->queue_mutex) { - size =3D iov_size(elem->in_sg, elem->in_num) - - sizeof(virtio_snd_pcm_status); buffer =3D g_malloc0(sizeof(VirtIOSoundPCMBuffer) + size); buffer->elem =3D elem; buffer->vq =3D vq; --=20 2.47.3 From nobody Tue Apr 21 14:38:43 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1776661709; cv=none; d=zohomail.com; s=zohoarc; b=Cwq01vbfxQOY7Zi85tcsv6qg9GYzltr0ii5QLPwf2SwdM3LKmB9tqGI4wdMfTmASa5bSJFxSiZDSShnXspVTvILdZhu14gN/pvg7xIVl1dfWbxp/8jqZO5nyg/nDm92JPuZA0JiDeq49a33meHVK0yoNKQoOKKjRdaHvV5SB7mU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1776661709; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=BwyGpcxIm+U3udOJ+6cB8zSHqyzc689Y7MjRe26X6L4=; b=QK1UEmn/W0wcO2aaSEizvVcGjdamOl7cOWiJ2ZRp4juJpZtRwl9nfyn0RSFx0XUEaGMk8MK8ngNQeBR+AX280adax16CPR2mwZJ/sv4DsmQcaJoxHTybY3q5uqxHckN5oZLJkmFB3u/T1sO7o1YLzg6409loCUvgrh9Ce3wBhQc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1776661709827514.7823342321361; Sun, 19 Apr 2026 22:08:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wEgqx-0004sC-Vf; Mon, 20 Apr 2026 01:07:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wEgqu-0004qY-BA for qemu-devel@nongnu.org; Mon, 20 Apr 2026 01:07:20 -0400 Received: from mail-wm1-x332.google.com ([2a00:1450:4864:20::332]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wEgqr-0002az-E9 for qemu-devel@nongnu.org; Mon, 20 Apr 2026 01:07:20 -0400 Received: by mail-wm1-x332.google.com with SMTP id 5b1f17b1804b1-4891b0786beso5315555e9.1 for ; Sun, 19 Apr 2026 22:07:13 -0700 (PDT) Received: from [127.0.1.1] (athedsl-4440559.home.otenet.gr. [79.129.177.223]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-43fe4e3a341sm28886954f8f.24.2026.04.19.22.07.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Apr 2026 22:07:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1776661632; x=1777266432; darn=nongnu.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=BwyGpcxIm+U3udOJ+6cB8zSHqyzc689Y7MjRe26X6L4=; b=GcH/W/zAeLQow3QxMQbYzyn/3kS3G4TTxXtWSpHlpw0n1GDDYwSyjlP+Qb89ZbPnpi kY3hDWW7x2pJkUdDiRuoVxyP+wrF2c1iISdtp5R5wmU/8kt4gbedCfbYwA2cIHc0iP40 CCA0HhgRWy0F1YZUV9M/PnTDkoZa3ciUwQy0PNaoToxOvRNc+0V6VoteOFbQ5TP3r6Ve Z6/qeeGMthd0O/e6EgioECkf4hi/7wB4hm+Gqt4oeLDEpmqQrwO4q+GyXIdy5RboNnDu 436rWmkmvijJU3UDvmCSiV4KaTtWBssG4vVXuqILMjt+INdO02PSJSYxZVPwUuzoB/m8 mBkQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1776661632; x=1777266432; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=BwyGpcxIm+U3udOJ+6cB8zSHqyzc689Y7MjRe26X6L4=; b=bDXcwLI91sh+xcv2jo1CZLCxTxnb8D7hKegCVVYXFaGmA0FGK/qqoPf+wrh2DFsCqV i0wX5lPQwwdNwhdEK452yrEdjwrdJ4kG3fdoxDmGttjJ2JuMkRMX6nCEKk9EVoeMiAo8 b6oL8FeNT254FmeYMOr1QLqmljZVxC+VxBOa5JQnBh3YGQc/GK8MoK6yiMKWFB478NEi ImwKxtjKD5mVKPAt31H3BdkCOm+gfKTC1cO2/azwCGMLXSw3peSBs9nbVzbepsYbec+M lYxHmp/PCgJGAWBpqSK091RPuzpQV6q4VahCMwWUjcvN8tB4NFY/vYH2nVmzcTCgFH00 Oz1Q== X-Gm-Message-State: AOJu0Yz43QU/scTIogfiDaMc15Ec27dX726m3LkdmWKfkbQraMPSbfWi N0PimOCOlHCQLrxBBx1wVLek0YeaKpCN7H+IQdlz4zaYq+u8oy1f7iMHmFVz68KgkQBUgyLYMiU J2k5s7i8= X-Gm-Gg: AeBDieuYUyMYBOv3vMrBMQzK4XoKJOfDU5hIi0J8SRmKXVHdvHpJL7+8Px35cXx5pnA PwanH6bpYHE02Jm289IlwPBKZqLFqgA8P5/QnrpIVaxCJmQoU3PURK9JDc6WeK/urKKvWchE6gx PWQ/Cr1JXB77kggdbL30yJEhaKTu5DXoxJ6Ib117oZzBIpM/o9Exp7yr8WvTkxDWJOKLsq4q98H SR1AphJ5MISF7lXDYNsorpIZoqtGOAp3O/PWNILnF7GLFoPl9VCIfwyWWJCt1jhRJDlTO0GY53s X+kunBlNZbRRMQo00ccxwV4r1ZqyQpoH8uC74PZyg2jQ4zYd5VQP7rj50oO5WZv6nyjshOuI8EH LyTgQNODkz0bdWepNoVYo40j5juVnsAqKchzRkm7nvgVwsOGs4l2g0UnDQIS9KNBFP/QvzqLD2w dEnEBKLxHs2FWaGUZ3znFYDZZOrbd9+NojlMHA2yla5y3H/ymg7x2UmDlir/glzk14kOCQFetgn Yi45ZxDCBbx/qhtoRo1W1SV3NRiy2kdiwwDB7IJ0osb7m9Nx20= X-Received: by 2002:a05:600c:3110:b0:488:8c89:cfaa with SMTP id 5b1f17b1804b1-488fb73841dmr178046755e9.3.1776661631947; Sun, 19 Apr 2026 22:07:11 -0700 (PDT) From: Manos Pitsidianakis Date: Mon, 20 Apr 2026 08:07:06 +0300 Subject: [PATCH v3 2/2] virtio-snd: check for overflow before g_malloc0 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260420-virtio-fixups-v3-2-07aef1eff9d2@linaro.org> References: <20260420-virtio-fixups-v3-0-07aef1eff9d2@linaro.org> In-Reply-To: <20260420-virtio-fixups-v3-0-07aef1eff9d2@linaro.org> To: qemu-devel@nongnu.org Cc: Gerd Hoffmann , "Michael S. Tsirkin" , =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= , =?utf-8?q?Alex_Benn=C3=A9e?= , Richard Henderson , qemu-stable@nongnu.org, Manos Pitsidianakis X-Mailer: b4 0.14.2 X-Developer-Signature: v=1; a=openpgp-sha256; l=2786; i=manos.pitsidianakis@linaro.org; h=from:subject:message-id; bh=+9Dhd+SEfK8bKKIwFEcKs73DtTFYq0bCyKTuZMmWZ7Q=; b=LS0tLS1CRUdJTiBQR1AgTUVTU0FHRS0tLS0tCgpvd0VCYlFLUy9aQU5Bd0FLQVhjcHgzQi9mZ 25RQWNzbVlnQnA1YlI4NnVkVmgzd01BeGxRZ2dVZEVhV3d1ZTUwCjRiMkxXZGFsbG5zd3ZOcWhj TnFKQWpNRUFBRUtBQjBXSVFUTVhCdE9SS0JXODRkd0hSQjNLY2R3ZjM0SjBBVUMKYWVXMGZBQUt DUkIzS2Nkd2YzNEowQjFCRC85dHBlMVNiclVEOHJ4cmJuVGlvVXFGdmJvNGNldjVZRVNTaTU1VQ p5c1o4UHpBcjU2cDFwdkJ6R0o5NEhYNFVCeWVRMVBTS2M0cXljNGYxUVNMQWJqbVkyZVhmTFp2V U56ckxnWG05ClpEZmM0dWdnbHBSWE1Ha2t6UFN2TUFybWMxcjQ1UVNXZkFtT2pGdGkyTngvb1R6 ZVREcm43L2ZqWC8zZ24rOVQKZzJYKy9HazRuR2pJQmFMOEcrTWhTQklIZVdhMkQ5RWxFaSsyWUc rbUJkUEhySVpBRXJJVzdTSFRNeTJ0TUs1Rwp4SVQ0alN5TThxYVNJaUNVRXk1SHhQK0dkOFFmVz NRUnp1UzA2R2hNbmxVNmo0NmUzR3F3QnA2ak00eU8vbE0wCkJDQXY0V3VQYlF0c0Q1Z3dmQlhEa XYyV3FONURicVRqRjNyQkk2MUVIdHZEOSs3OW5tUzE2TnpMWml6VGd5cTMKQzVqTXBxZGZRUUR1 Q2NuTCtCb011REw1UGE2MTNieUtVdjdzd3pyVnZja2kvMnNmYy9UMU5PcDZ5S0trZkJkZwovOEV vN1dxNXd4S09na0t1ODFYYjgzU0xpcDJpc1lvb1gzOXNZd0xjZ3l3S3F6b2JCUDJvUE1CaERTNS t5Mk1ECkN5M0t2ZEgySnprUHlCb3p2azlZdVh6RmFLUTRDNEJyYXhHVFpSRlJMRzUza1JpZytOO C9ESTVmcjdTdnNrSlcKSk10VWJQZWtraUF0K1hvTzJVZzdPdWVLVHNEZ3pFOTIxZnVVUk15aVM5 QnErWUQwMGlUaHo4T1h3Q1lsT2JMMQo3RHVjY0J4cW15VXNmbEdxYXYzLzMzWGtsajNSSHF0YlV 1R3NRZG1tQWZHS0FpY3RCNFUwRGYrckNpdlF4dWV6CkkvOC9ndz09Cj1qUDJVCi0tLS0tRU5EIF BHUCBNRVNTQUdFLS0tLS0K X-Developer-Key: i=manos.pitsidianakis@linaro.org; a=openpgp; fpr=7C721DF9DB3CC7182311C0BF68BC211D47B421E1 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::332; envelope-from=manos.pitsidianakis@linaro.org; helo=mail-wm1-x332.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1776661712005158500 Coverity points out one g_malloc0 overflow, but it seems to be a false positive. Add a check to it regardless to fortify the code, and also add checks for every other g_malloc0 use. Resolves: Coverity CID 1547527 Signed-off-by: Manos Pitsidianakis --- hw/audio/virtio-snd.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/hw/audio/virtio-snd.c b/hw/audio/virtio-snd.c index 93fbcfb43f7fdcfd5c164b496015da743822f5eb..694bcebb60f6c866346470672cc= 798b3271ae34f 100644 --- a/hw/audio/virtio-snd.c +++ b/hw/audio/virtio-snd.c @@ -850,7 +850,7 @@ static void virtio_snd_handle_tx_xfer(VirtIODevice *vde= v, VirtQueue *vq) VirtIOSound *vsnd =3D VIRTIO_SND(vdev); VirtIOSoundPCMBuffer *buffer; VirtQueueElement *elem; - size_t msg_sz, size; + size_t msg_sz, size, tmp; virtio_snd_pcm_xfer hdr; uint32_t stream_id; /* @@ -880,6 +880,8 @@ static void virtio_snd_handle_tx_xfer(VirtIODevice *vde= v, VirtQueue *vq) if (msg_sz !=3D sizeof(virtio_snd_pcm_xfer)) { goto tx_err; } + assert(iov_size(elem->out_sg, elem->out_num) >=3D msg_sz); + size =3D iov_size(elem->out_sg, elem->out_num) - msg_sz; stream_id =3D le32_to_cpu(hdr.stream_id); =20 if (stream_id >=3D vsnd->snd_conf.streams @@ -892,9 +894,11 @@ static void virtio_snd_handle_tx_xfer(VirtIODevice *vd= ev, VirtQueue *vq) goto tx_err; } =20 + /* Check for g_malloc0 overflow. */ + if (!g_size_checked_add(&tmp, sizeof(VirtIOSoundPCMBuffer), size))= { + goto tx_err; + } WITH_QEMU_LOCK_GUARD(&stream->queue_mutex) { - size =3D iov_size(elem->out_sg, elem->out_num) - msg_sz; - buffer =3D g_malloc0(sizeof(VirtIOSoundPCMBuffer) + size); buffer->elem =3D elem; buffer->populated =3D false; @@ -932,7 +936,7 @@ static void virtio_snd_handle_rx_xfer(VirtIODevice *vde= v, VirtQueue *vq) VirtIOSound *vsnd =3D VIRTIO_SND(vdev); VirtIOSoundPCMBuffer *buffer; VirtQueueElement *elem; - size_t msg_sz, size; + size_t msg_sz, size, tmp; virtio_snd_pcm_xfer hdr; uint32_t stream_id; /* @@ -977,6 +981,10 @@ static void virtio_snd_handle_rx_xfer(VirtIODevice *vd= ev, VirtQueue *vq) goto rx_err; } size -=3D sizeof(virtio_snd_pcm_status); + /* Check for g_malloc0 overflow. */ + if (!g_size_checked_add(&tmp, sizeof(VirtIOSoundPCMBuffer), size))= { + goto rx_err; + } WITH_QEMU_LOCK_GUARD(&stream->queue_mutex) { buffer =3D g_malloc0(sizeof(VirtIOSoundPCMBuffer) + size); buffer->elem =3D elem; --=20 2.47.3