From nobody Sun Jul 26 12:29:12 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1782144738; cv=none; d=zohomail.com; s=zohoarc; b=HFaUjYpxzx6pnSd/DPW2V5Z+11aI0rhYKO3t64AWJv4gqLSSuAz0os2v1ja+L1bFYUB9ah9WG3ae1ag/rVuRlgdtDolqYt0eJR1cz5eGYAUY3VYLLbfZLCVt3C5MpwA/SDoWjU5rbSBNfBJjO2rC93BGt1Z+3DToDAnwuup3U40= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782144738; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ma6dsYdCVPYfWQWDqH3DZDdyXl9n2kbNGsk9i4sYk1c=; b=VMVTldm6y+uCWhBsp+7Smg4IG1Y0SgVv2FDyfk3h9dgBSb8o29eIBD9UyvaBe0GWVQBIP+UbAdZPLvJvS9jEjFWbn0Z8HCD0EYz2LgWYwti5iyrc8avROIXyG7ReAkwczTuSvu9OqXIPhOOlgG0TR6afgZLl7fib9kRvaluHX30= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782144738110405.34306033243297; Mon, 22 Jun 2026 09:12:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wbhFg-0001sK-6B; Mon, 22 Jun 2026 12:12:00 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wbhFa-0001rn-M0 for qemu-devel@nongnu.org; Mon, 22 Jun 2026 12:11:54 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wbhFY-0000Be-GA for qemu-devel@nongnu.org; Mon, 22 Jun 2026 12:11:53 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-180-9QDKfWYaM7OyNSkuhEYAyg-1; Mon, 22 Jun 2026 12:11:48 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id CDC73195604A; Mon, 22 Jun 2026 16:11:47 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D023536512; Mon, 22 Jun 2026 16:11:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1782144710; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=ma6dsYdCVPYfWQWDqH3DZDdyXl9n2kbNGsk9i4sYk1c=; b=KCO/o47F3JAELNADONxV3MjMkXnKaTZbOy0syE0tI0+SOTZX4rKtv2GhT8V6WU4jgwjpKv +xyyg6bVApuIJQKxcs/hlz0Ukc8EP/SqSp7XmaMlQmN5uR2/sW5gw3GJgIhvvcn27UuIZ4 kiTa2YTykcU8AcKQd48g1ENdd4Lai8o= X-MC-Unique: 9QDKfWYaM7OyNSkuhEYAyg-1 X-Mimecast-MFC-AGG-ID: 9QDKfWYaM7OyNSkuhEYAyg_1782144708 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Laurent Vivier , "Michael S. Tsirkin" , Paolo Bonzini , Amit Shah , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , qemu-stable@nongnu.org Subject: [PATCH] hw/char/virtio-serial-bus: fix guest-triggerable OOM in control_out() Date: Mon, 22 Jun 2026 18:11:44 +0200 Message-ID: <20260622161144.2883799-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 8 X-Spam_score: 0.8 X-Spam_bar: / X-Spam_report: (0.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1782144739882158500 Content-Type: text/plain; charset="utf-8" A malicious guest can craft virtqueue descriptors with arbitrary lengths. control_out() calls iov_size() on the guest-supplied scatter-gather list and passes the result directly to g_malloc(), allowing a guest to force QEMU to attempt multi-gigabyte allocations and crash the host process. Fix this by copying at most sizeof(struct virtio_console_control) into a stack-local variable instead of allocating a buffer sized by the guest. handle_control_message() only accesses the fixed-size id, event, and value fields, so no data beyond the struct was ever needed. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3585 Signed-off-by: Laurent Vivier --- hw/char/virtio-serial-bus.c | 34 +++++++--------------------------- 1 file changed, 7 insertions(+), 27 deletions(-) diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c index cd234dc6db1d..c1973f0248fc 100644 --- a/hw/char/virtio-serial-bus.c +++ b/hw/char/virtio-serial-bus.c @@ -344,22 +344,16 @@ void virtio_serial_throttle_port(VirtIOSerialPort *po= rt, bool throttle) } =20 /* Guest wants to notify us of some event */ -static void handle_control_message(VirtIOSerial *vser, void *buf, size_t l= en) +static void handle_control_message(VirtIOSerial *vser, + struct virtio_console_control *gcpkt) { VirtIODevice *vdev =3D VIRTIO_DEVICE(vser); struct VirtIOSerialPort *port; VirtIOSerialPortClass *vsc; - struct virtio_console_control cpkt, *gcpkt; + struct virtio_console_control cpkt; uint8_t *buffer; size_t buffer_len; =20 - gcpkt =3D buf; - - if (len < sizeof(cpkt)) { - /* The guest sent an invalid control packet */ - return; - } - cpkt.event =3D virtio_lduw_p(vdev, &gcpkt->event); cpkt.value =3D virtio_lduw_p(vdev, &gcpkt->value); =20 @@ -457,41 +451,27 @@ static void control_in(VirtIODevice *vdev, VirtQueue = *vq) =20 static void control_out(VirtIODevice *vdev, VirtQueue *vq) { + struct virtio_console_control cpkt; VirtQueueElement *elem; VirtIOSerial *vser; - uint8_t *buf; size_t len; =20 vser =3D VIRTIO_SERIAL(vdev); =20 - len =3D 0; - buf =3D NULL; for (;;) { - size_t cur_len; - elem =3D virtqueue_pop(vq, sizeof(VirtQueueElement)); if (!elem) { break; } =20 - cur_len =3D iov_size(elem->out_sg, elem->out_num); - /* - * Allocate a new buf only if we didn't have one previously or - * if the size of the buf differs - */ - if (cur_len > len) { - g_free(buf); - - buf =3D g_malloc(cur_len); - len =3D cur_len; + len =3D iov_to_buf(elem->out_sg, elem->out_num, 0, &cpkt, sizeof(c= pkt)); + if (len =3D=3D sizeof(cpkt)) { + handle_control_message(vser, &cpkt); } - iov_to_buf(elem->out_sg, elem->out_num, 0, buf, cur_len); =20 - handle_control_message(vser, buf, cur_len); virtqueue_push(vq, elem, 0); g_free(elem); } - g_free(buf); virtio_notify(vdev, vq); } =20 --=20 2.54.0