On Mon, 2026-06-22 at 11:20 +0200, Christian Borntraeger wrote:
> The stsi 3.2.2 page is being prepared by the kvm module and the size is
> clamped by the kernel. As the memory is mapped in the guest, another
> guest VCPU could race and overwrite the count and messing up the move
> operation. For any out of bound count, fall back to the kernel buffer.
>
> Cc: qemu-stable@nongnu.org
> Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
> ---
> target/s390x/kvm/kvm.c | 9 +++++++++
> 1 file changed, 9 insertions(+)
Looks right to me.
Reviewed-by: Eric Farman <farman@linux.ibm.com>
>
> diff --git a/target/s390x/kvm/kvm.c b/target/s390x/kvm/kvm.c
> index ed8cd6b410..a3835573bb 100644
> --- a/target/s390x/kvm/kvm.c
> +++ b/target/s390x/kvm/kvm.c
> @@ -1791,6 +1791,15 @@ static void insert_stsi_3_2_2(S390CPU *cpu, __u64 addr, uint8_t ar)
> } else if (s390_cpu_virt_mem_read(cpu, addr, ar, &sysib, sizeof(sysib))) {
> return;
> }
> +
> + /*
> + * The memory was filled by the kernel but mapped into the guest.
> + * If something is fishy, do not touch the buffer.
> + */
> + if (sysib.count == 0 || sysib.count > ARRAY_SIZE(sysib.ext_names)) {
> + return;
> + }
> +
> /* Shift the stack of Extended Names to prepare for our own data */
> memmove(&sysib.ext_names[1], &sysib.ext_names[0],
> sizeof(sysib.ext_names[0]) * (sysib.count - 1));