From nobody Sun Jul 26 11:06:40 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1782983184; cv=none; d=zohomail.com; s=zohoarc; b=G9oV1ak4I3pGDIao6/aMl8LJhv6vk7gDnsCeXfaU7VEFzsnVOFuHcWNuI1FAmIpVzu0WO/4B5USj0WIvGcpyWTv3pUxWwsNbGyUJEWkT2DECt2B4Gh9hCxQa38gAwo+/hOKhoFYQOYGjOuev1qU4IYfL4+PRoYEWRLqDLrN+RlA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782983184; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ha4XTpT+RqnbRJPQX2PzEMZ+ZMG44RCEdXff0/ITp0A=; b=XE9l5uoOTluJaUzwqQX/1XGhkoDF/h8hE8WLI24Kn1mHLTSDBsTUmLZbiBlCe4oa69H9xGSTwujreTZihczSeOF2vbPmDRNX2DVTS8Bpbxhi4O2//LGosfHCuGZerulCN3XnvWFjYQDsFlEhGW7xiUW5rEquchnsfS6jFuJy6kE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782983172891931.4264728642257; Thu, 2 Jul 2026 02:06:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfDMY-0006g4-28; Thu, 02 Jul 2026 05:05:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfDMW-0006fN-CS for qemu-devel@nongnu.org; Thu, 02 Jul 2026 05:05:36 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfDMU-0007HO-Qd for qemu-devel@nongnu.org; Thu, 02 Jul 2026 05:05:36 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-461-dEA2y4UTO3OeFq46pSadfw-1; Thu, 02 Jul 2026 05:05:30 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 73B3B188E6F1 for ; Thu, 2 Jul 2026 09:05:29 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.8]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 019F23000B51; Thu, 2 Jul 2026 09:05:28 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id A43491800D63; Thu, 02 Jul 2026 11:05:27 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1782983133; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ha4XTpT+RqnbRJPQX2PzEMZ+ZMG44RCEdXff0/ITp0A=; b=OAUVxjA5XpQX4ZALuDdWD0hUmyEb9INb2sniG/xybCAGVWBjXQt8KX1bjXH82PrDzrn8lJ zJVEeSSGxHU5ow9RX4QNbexAjEJzGwHs4D3K+8s8oSWDh+bVVosfsSjCDJMuHk1gDukxJD qM2T++/tknqk7cnr5lsgIyfghXDoIXE= X-MC-Unique: dEA2y4UTO3OeFq46pSadfw-1 X-Mimecast-MFC-AGG-ID: dEA2y4UTO3OeFq46pSadfw_1782983129 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Gerd Hoffmann Subject: [PATCH 1/2] hw/uefi: add sanity check Date: Thu, 2 Jul 2026 11:05:25 +0200 Message-ID: <20260702090527.4167310-2-kraxel@redhat.com> In-Reply-To: <20260702090527.4167310-1-kraxel@redhat.com> References: <20260702090527.4167310-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -24 X-Spam_score: -2.5 X-Spam_bar: -- X-Spam_report: (-2.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1782983187698158500 Content-Type: text/plain; charset="utf-8" Verify the passed buffer has the minimal required length before reading the size field + verifying the total length. Fixes: CVE-2026-58581 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3614 Signed-off-by: Gerd Hoffmann --- hw/uefi/var-service-policy.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/hw/uefi/var-service-policy.c b/hw/uefi/var-service-policy.c index 58da4adbebaf..989bf87ddb86 100644 --- a/hw/uefi/var-service-policy.c +++ b/hw/uefi/var-service-policy.c @@ -276,6 +276,9 @@ static uint32_t uefi_vars_mm_check_policy_register(uefi= _vars_state *uv, uefi_var_policy *pol; uint64_t length; =20 + if (mhdr->length < sizeof(*mchk) + sizeof(*pe)) { + return uefi_vars_mm_policy_error(mhdr, mchk, EFI_BAD_BUFFER_SIZE); + } if (uadd64_overflow(sizeof(*mchk), pe->size, &length)) { return uefi_vars_mm_policy_error(mhdr, mchk, EFI_BAD_BUFFER_SIZE); } --=20 2.55.0 From nobody Sun Jul 26 11:06:40 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1782983176; cv=none; d=zohomail.com; s=zohoarc; b=Yu7Oj7WGJGFGNx5B9mx0taA/hG93/Ovi8hmE0JsFSQQs0ThhrOlWZ0Eld6Y70ZlzKIi9+FCOeoGmgOs9BFpcfe0wTPfNgwQRMovQSsx6NrgfWRMKgUZl7lPVw6E3D3JKQFkYr4dtDJ+TVSSnEiZ8HxX9KS9covMRswpQNn8ieWQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1782983176; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RHoYf9UciMVlf0S4qtSDUnJeyItIQPrkFzW8qJrque8=; b=d4rih/sSE68XNvKdD3yIU3TMd7Qi/h6H2h/rnKXGQ4Q3faraXwI2xk2Ijn0x0GVJTkFPm3HXCufk2+LnY0BK5FKOGU0wHrsnfEk3EmGslQHvz2tTygTE2kxeEGmYW6qa+SgoGXlh1Ui+Z19YfPwD3QMwwPNbsS9JiiKzPFcymwU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1782983164220354.5609831619332; Thu, 2 Jul 2026 02:06:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wfDMW-0006fT-Ib; Thu, 02 Jul 2026 05:05:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfDMV-0006ey-3q for qemu-devel@nongnu.org; Thu, 02 Jul 2026 05:05:35 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wfDMT-0007HC-M2 for qemu-devel@nongnu.org; Thu, 02 Jul 2026 05:05:34 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-608-FkwFr9wONBqzk22P_qmWUg-1; Thu, 02 Jul 2026 05:05:31 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E71EB1944B00 for ; Thu, 2 Jul 2026 09:05:30 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.8]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 704B4180058D; Thu, 2 Jul 2026 09:05:30 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id B32331800DE4; Thu, 02 Jul 2026 11:05:27 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1782983133; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RHoYf9UciMVlf0S4qtSDUnJeyItIQPrkFzW8qJrque8=; b=fzS/tvuEGoMMBLkvbL8Ow6W9Z10KkCEWsiXsKAh9YQeZOpQdo3zFUlf1IFIafcxCA2RiW1 3Ke08DIXscGSRc82SJtksKtRm6yygvJ+1FzGggQSwTy0bFR7g16olceEK8h7ITAHWz6OXI /W/AyuUDHXwS4F4aLI8P+29Z9xMdrAg= X-MC-Unique: FkwFr9wONBqzk22P_qmWUg-1 X-Mimecast-MFC-AGG-ID: FkwFr9wONBqzk22P_qmWUg_1782983131 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Gerd Hoffmann Subject: [PATCH 2/2] hw/uefi: disable debug function Date: Thu, 2 Jul 2026 11:05:26 +0200 Message-ID: <20260702090527.4167310-3-kraxel@redhat.com> In-Reply-To: <20260702090527.4167310-1-kraxel@redhat.com> References: <20260702090527.4167310-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 8 X-Spam_score: 0.8 X-Spam_bar: / X-Spam_report: (0.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1782983180044158500 This was never meant to be active in production builds. It's a code path not hit on a normal boot (OVMF wouldn't try variable updates which are not allowed), so this went unnoticed. Wrap the call into "if (0)" so it never actually called, but we also do not get dead code warnings and can keep the printing function in the code base for debugging. Also fix the name printing to not overrun the entry size. Fixes: CVE-2026-58582 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3615 Signed-off-by: Gerd Hoffmann --- hw/uefi/var-service-policy.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/hw/uefi/var-service-policy.c b/hw/uefi/var-service-policy.c index 989bf87ddb86..f78c8f01d62a 100644 --- a/hw/uefi/var-service-policy.c +++ b/hw/uefi/var-service-policy.c @@ -40,11 +40,12 @@ const VMStateDescription vmstate_uefi_var_policy =3D { static void print_policy_entry(variable_policy_entry *pe) { uint16_t *name =3D (void *)pe + pe->offset_to_name; + uint16_t *end =3D (void *)pe + pe->size; =20 fprintf(stderr, "%s:\n", __func__); =20 fprintf(stderr, " name =C2=B4"); - while (*name) { + while (*name && name < end) { fprintf(stderr, "%c", *name); name++; } @@ -173,7 +174,9 @@ efi_status uefi_vars_policy_check(uefi_vars_state *uv, pe =3D pol->entry; =20 uefi_trace_variable(__func__, var->guid, var->name, var->name_size); - print_policy_entry(pe); + if (0 /* development and debugging only */) { + print_policy_entry(pe); + } =20 if ((var->attributes & pe->attributes_must_have) !=3D pe->attributes_m= ust_have) { trace_uefi_vars_policy_deny("must-have-attr"); --=20 2.55.0