From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289291; cv=none; d=zohomail.com; s=zohoarc; b=A+ozSXKRsOAm74XR+4HsDRUMqHVVqia13H0MfPeMHO5gRyNjE3O1eW92+GaCQ1MZahFJKOHI/9iK98Fu3V91e3Dh8jBq3OHz8wEP4HtQ9GfFEbVRnvX8+ssqMQ05z7Jy9BshDEv0aIwkSHje9KnaFDi1pCRToAbceLPhRIiej18= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289291; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=sQ0kpNbqQmh7Rqy8oHbfrgrmT4Ki1WOkGKlW/sPYSzQ=; b=JIU5ZmQxpvIPH25Ps/KbdrvNGUj0FsoG0N1I0xudEi5Wt+Z7HZBdyoJO7Et/u3sRMIZeGlLh84QWVxT4MlMk94Yi1T+a/rLwoppG+6l/fJSjfB4Cn/rpAQhGSfX8Mik65mA1UuhX0coXwWhcQJLZ459G0CQqzknlA3e0bAHyreY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178428929131035.65574364743429; Fri, 17 Jul 2026 04:54:51 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh87-0003fB-33; Fri, 17 Jul 2026 07:53:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh85-0003ev-FB for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:21 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh7y-0003OK-TM for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:15 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-480-xGXoTz6MM7igQ4H5Vn7IRA-1; Fri, 17 Jul 2026 07:53:10 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 34D91180074E for ; Fri, 17 Jul 2026 11:53:09 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 030FA1955D86 for ; Fri, 17 Jul 2026 11:53:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289194; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=sQ0kpNbqQmh7Rqy8oHbfrgrmT4Ki1WOkGKlW/sPYSzQ=; b=b9Ce6NNX98cpp3LTieudE9PzzneMY10RYHmV8kl5L8aeZ3yMtl6hr9IuhNO9+7qSz+Ahc+ DuZxg+IlChFsl/KXNqKhchAzdcXRikBRhZtgRGDj3ypoS1HNv7QdaSsb/cb5vUYf0Ol5ng PFAzU1+3WsZg+lnN5oNblFqNnyqLzkg= X-MC-Unique: xGXoTz6MM7igQ4H5Vn7IRA-1 X-Mimecast-MFC-AGG-ID: xGXoTz6MM7igQ4H5Vn7IRA_1784289189 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:40 +0400 Subject: [GIT PULL 01/15] i386/tdx: fix uninitialized variable warning in tdx_check_features MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-1-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=966; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=R6iO6NRN+7wwybY73JE3CJcD1P+wCpJvUpV059G3hA0=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheZpW9xU8L78nAtghp79F2IABJZFO1GRFzpM G1UyvxB2YGJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmQAKCRDa6OEJdZac 5auKD/0eyQ3FeHOxEVOXXc2IxeSu3BfcD/Pa0dAZ3GDbUqUeAxfy/rC/JkTCd1myPNmcSv6UlZt E+/qEHG9Dyblb6hgafgFrqBKh25jHm/z/xQ0bP0/uI3hBJIIi2/kB+QnWqbUkQOpAGprsPQp7oD DrClKG52YlAKyplZFe+qQbJY423fGG5zDG0BwWgShAPOITcwDKFqFT7HaDc1OJJSy7+k0eJxnrz O8DkplhkOBds0x9A8mgP5mdnGkftTv1TJCd0gfLVmdHA0kScEyiXvi55QgE7FpMLV/xFQwR6UNo Aholi5GTyjZM74SU33KkGNdmw/BBaCLPq8tPWEo7LW9BpnrqQoHjPBFJ/BrQbdxxbN+G/7t+v9V xETNSkC0RkaubRTd/kMlZQ1UbC+Ow3SxAetrYILhqi0grJBr3w8DbqFeqI2kJczjdKeqth8cokY YopYxvbUZnX1TMvkSMIexyhvVWoNanW33LUhGkqOIYnSXibYam8hcvwCMKna8X5Ek6J/ZOfQVK6 xHh6Cmz/zpDJLSV2pMq50bFDj2y8UvFYc/jF3Iz6TAdHGcuCswnKmyf63cCXn2N8HgncuYfygUi lDjDC+yB5aKLnGsKWhzq+XydY7BW/Gwlh+K6aYAkRkEkdF+p5mK8MITOMKclj7UXTcrulCT+tLO OC9dxXGnzz1wPcg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289292812158500 tdx_fetch_cpuid() only sets the output ret parameter on the error path. GCC cannot prove that r is always initialized before use in the caller, triggering -Werror=3Dmaybe-uninitialized. Initialize r to -1 to silence the warning. Fixes: 228e40f33048 ("i386/tdx: Fetch and validate CPUID of TD guest") Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andre Lureau --- target/i386/kvm/tdx.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/target/i386/kvm/tdx.c b/target/i386/kvm/tdx.c index c9c3b05d5fe..8294dbde3aa 100644 --- a/target/i386/kvm/tdx.c +++ b/target/i386/kvm/tdx.c @@ -887,7 +887,7 @@ static int tdx_check_features(X86ConfidentialGuest *cg,= CPUState *cs) FeatureWordInfo *wi; FeatureWord w; bool mismatch =3D false; - int r; + int r =3D -1; =20 fetch_cpuid =3D tdx_fetch_cpuid(cs, &r); if (!fetch_cpuid) { --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289221; cv=none; d=zohomail.com; s=zohoarc; b=FYwVRM9fyWkAE7Kfxf4x3H4WVx1aq2e8X/GcBf0txe6ba4/tZz5m/ng7xkrvtC11VgKuasdoqAf3W2y097EmvEF5eGa9WVdqJpDjQcfchmMN/RcEp05MXj0Q7TdHVx/GroWF1fhTH1TxGMAO9/NENDGdQyTKwMMXFr0aH4YB6vw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289221; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=vZ1WP+O9s6QEcDNkMenKtPj1/KWw7oDwlYf4583qKxQ=; b=Cvyij6MoSK8XzPiLsu+sFEKZTLxhO0nKFMIN9no8XkkIyef0bzMIsXlFDSAauMU7jGbR9tLZZXkJQnirmmvAdlIGBDUm6RECCxU7rfaIpfQX+lrihnyGx+t2NgZa0YVbIHZ1/pPfVGA7iUOfqokzPU+0I5NRe2HJiT9vJiYlxI4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289221655739.3462561912565; Fri, 17 Jul 2026 04:53:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh88-0003fY-GF; Fri, 17 Jul 2026 07:53:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh87-0003fA-0v for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:23 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh85-0003Of-8x for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:22 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-611-dk8wSvBaOPGAVHzA0Wz0Iw-1; Fri, 17 Jul 2026 07:53:15 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id F27A7180074E for ; Fri, 17 Jul 2026 11:53:14 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DBDF8180034C for ; Fri, 17 Jul 2026 11:53:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289197; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vZ1WP+O9s6QEcDNkMenKtPj1/KWw7oDwlYf4583qKxQ=; b=fh23B/5Rdem5A6SZqmBcIJGdaB5Gqx4DQd8psW/SyDeBjSFTyqiETrqTFqGNX8BtaAfCga 8VnU0kMCawU3IB+Z3U/Zo9acYZ1YBLy9zpdA9Eoqx2/lt0jPGmwhlgPctvWlc0mKe6d0T7 NwkWfjvkCgjuptpRXstjsg8vDS08mps= X-MC-Unique: dk8wSvBaOPGAVHzA0Wz0Iw-1 X-Mimecast-MFC-AGG-ID: dk8wSvBaOPGAVHzA0Wz0Iw_1784289195 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:41 +0400 Subject: [GIT PULL 02/15] ui/vnc: fix OOB write in vnc_refresh_lossy_rect MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-2-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2067; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=d9iNnmvHwz9V5eb/jktzHMJMRQuIJZmRJLaiZr8hjbc=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheZIcuGkn26LiPnDDQ9Py5Q73jtihRboQE+U f1umep+Qv+JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmQAKCRDa6OEJdZac 5b0OEACGtbJ/thrBFKZ1F1XYfmvdONWJUWbW7O77XtXr1X39W/WXC/oBd2mU7yY7fW27fLdE+C9 1gb4bMDQM7ZXXKyrUOqb+85xSz4+CYXyAZAl0JMuf3XD0zW7sWN+8v7PZbMjVkTlEUZ2GVDebJ0 cplqd7B7NpsH3/L8gIS2QFT1Ue+Wc3y2lu9QCrFmuCU9v2HoSJUYlW7qaluv1/VMlsKc/WWjY6D gjyyMID6E/4iDA8Bs3mbcFrY02QvHu9YE6/q4MO1LO5Y4Ul6IPzQejeLU91GTVVXA3lskthbPpm e8Kon9ohyWQFVfmmvhsgeoXkfvbSLtOQdQITI9Umzdoi/t4iIS39nT2fq7N4fwrQAjLKL6KjEtA NZjk1YszxecN68H6MOEtu88v+83hwQ679i3WRsLPMDiLVJ8ywLX7TtAWoegE691+T2F3ZQ90hiv tYmzF6FQH6LG9m0Z6PMQ5ieKR8qXVayRhzbOWQKJeTqYXSw/cXEfuMWl2K4TAJeiBxuxLBG6SHX TSCWBYXIRkuLoK+U8bAuafg+anOmBjs5C3gY9jTe1xdziYeVcZKAm7B+cUO2Cm79nuzur2yi8ZN kcQn7mFPx+to8z6p2zvkGbWKC9zAmRuSPdpEW7eCs6u06BzIsLDkrIf0QeW/SvD5kuDjNb6Tx9A 4eDBTFaF0cM5G6w== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289222640158500 vnc_refresh_lossy_rect() always marks a full VNC_STAT_RECT (64) rows as dirty when refreshing a lossy tile. When the display height is not a multiple of VNC_STAT_RECT (e.g. VNC_MAX_HEIGHT =3D 2160), the bottom tile is partial -- the last tile at y=3D2112 has only 48 valid rows. The unclamped loop writes to vs->dirty[2160..2175], past the end of the VNC_MAX_HEIGHT-sized array. Clamp the row count to the actual surface height so partial bottom tiles only mark valid dirty bitmap entries. Fixes: CVE-2026-48002 Fixes: 7d964c9d2fc6 ("vnc: refresh lossy rect after a given timeout") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3950 Reported-by: huntr bubble Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andre Lureau --- ui/vnc.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/ui/vnc.c b/ui/vnc.c index b2b69923b75..559d3954b87 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3004,10 +3004,18 @@ static int vnc_refresh_lossy_rect(VncDisplay *vd, i= nt x, int y) int sty =3D y / VNC_STAT_RECT; int stx =3D x / VNC_STAT_RECT; int has_dirty =3D 0; + int height =3D MIN(pixman_image_get_height(vd->guest.fb), + pixman_image_get_height(vd->server)); + int rows; =20 y =3D QEMU_ALIGN_DOWN(y, VNC_STAT_RECT); x =3D QEMU_ALIGN_DOWN(x, VNC_STAT_RECT); =20 + rows =3D MIN(VNC_STAT_RECT, height - y); + if (rows <=3D 0) { + return 0; + } + QTAILQ_FOREACH(vs, &vd->clients, next) { VncConnection *vc =3D container_of(vs, VncConnection, vs); int j; @@ -3022,7 +3030,7 @@ static int vnc_refresh_lossy_rect(VncDisplay *vd, int= x, int y) } =20 vc->worker.lossy_rect[sty][stx] =3D 0; - for (j =3D 0; j < VNC_STAT_RECT; ++j) { + for (j =3D 0; j < rows; ++j) { bitmap_set(vs->dirty[y + j], x / VNC_DIRTY_PIXELS_PER_BIT, VNC_STAT_RECT / VNC_DIRTY_PIXELS_PER_BIT); --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289237; cv=none; d=zohomail.com; s=zohoarc; b=Ips5xBMtFHxqLSP/fNnKJ6VTY2X6dxZuaLMs0k4nH6MKapgrPLHqiuTlfn/h2ezo30Yg8VbkSM/ePaBWV7oUGhGSxsCMeLyfJGiklrOuiWFs9Kit7/q8b/W3XeAvGhuBd+WlwZ/xNWLEa/80mIndubt6dHw5WgYUVWSGtmSwa7A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289237; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=mFwO8z45faH+SUf4z+vkV70f6AZle9l0fNeXfFpcE+Q=; b=cXyLiLHKutT/F6xpcRTC9FuF/cI7l6nV2q+XoDehfWkmvh12x8azMkyht28iXeLUS8gDblribjHwmQdvPXxafMP1GLMMWyg+793rNdqWCqPU+Z0bbm51Hub9dzfEipfHc1p4QQ2lTajXLHjUM5pgtOC7jXnRpjo+mAmi/iPSRSk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289237183150.07299234965274; Fri, 17 Jul 2026 04:53:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8C-0003lR-U9; Fri, 17 Jul 2026 07:53:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8B-0003io-EB for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:27 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8A-0003PO-0w for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:27 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-617-KB1ME8JgN8yG_BfQbBDWMA-1; Fri, 17 Jul 2026 07:53:20 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 11A661955D48 for ; Fri, 17 Jul 2026 11:53:20 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DDA59195604D for ; Fri, 17 Jul 2026 11:53:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289205; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mFwO8z45faH+SUf4z+vkV70f6AZle9l0fNeXfFpcE+Q=; b=LXmvKHqdmTnkgKqU5lTqXrIwzfbCtF/f2Xhm2taZGz/iDIGq6icqfpQbAFQWx9SExghQwQ xPyqfgm7MFZBwDu19L8hKmUFafrhUlauQgrzhjJe5YJr25LPcYd2JE9vpgTnPpknkn0+1P PGtl3Bn4jUdITlkcIQI8sJiC8CjcvX0= X-MC-Unique: KB1ME8JgN8yG_BfQbBDWMA-1 X-Mimecast-MFC-AGG-ID: KB1ME8JgN8yG_BfQbBDWMA_1784289200 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:42 +0400 Subject: [GIT PULL 03/15] ui/vnc: validate color shifts in SetPixelFormat MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-3-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1251; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=ORYeDgS/BTC2BlWLULACM9JIIWK8YOohLX9VzNModlc=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheZVLoi7xFu286r0O+0JfxUJAhH9CoY4pk/s yKdJ+wtypCJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmQAKCRDa6OEJdZac 5efnD/9wnAwQGGppZhLTWJfB190Mx2ehSqlB2bcc0DWH3O96NdN0mUAzZ1qzRMQJx/G8rAKvAwp 1FCwcRQk/6px7xTIiW9wMkVVPASIdyN3cScTerkj2H9Lyue7blbiF1COFwKtk8S/Lwy4bZAHP/z Afa3YS6Dsye8VvIsG94EkuduIBFmYlscihsMemFJXIpjx37w29QgztfEaJGcMF8lSHAzU3M+Ivb uYaRL36v0uR23PXSqYWeUW0Ae8ugrPB1vfuYurPWrgo5RuSgwX/9CpdKMKoRE04sWdlDY9VNwPT ypDdT2iov18ddRAV9FUTYkurSJKg8wdPFAER6GRM4C6c+6rd5y2FCQgVpALIOKYGUs9EYnyz/vf fC19leHBB/jjzFx8mu8VTbUWRkAd/jCJiUo4sHQJ9D/i2seBa6a+nGJ4O9hMVTo3bC3oALIbUtm 4UKq/7ex+l5pezamT+JFNjI5t261VaHY4Hf3+iziB08dXRQmhYQlvud9ZOdJ81hiUAy07bu9led uy2Qh728TQtxPNhNTs3bBDLCjlJp518PjOcTJpiKgxCEvc6rDX6+lZn4zSHF3WKlQZETl6Kcw79 jN794xH/7Nje3Hvyb0NhLh57hm539e4GR4tyWUZRjrx4RlIDmkFgAOC3glGAQIVLQzyojVnukuY Bx7HZH/Y5mL9Zkg== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289238576158500 A malicious VNC client can send a SetPixelFormat message with shift values >=3D 32, causing UB mask computation (e.g. red_max << red_shift where red_shift is 255). Apparently, this is not covered by -fwrapv. Reject color shifts >=3D bits_per_pixel || 32 before computing masks. Fixes: 9f64916da20 ("pixman/vnc: use pixman images in vnc.") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3948 Reported-by: huntr bubble Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andre Lureau --- ui/vnc.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/ui/vnc.c b/ui/vnc.c index 559d3954b87..9219f593d95 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -2276,6 +2276,13 @@ static void set_pixel_format(VncState *vs, int bits_= per_pixel, return; } =20 + if (red_shift >=3D bits_per_pixel || red_shift >=3D 32 || + green_shift >=3D bits_per_pixel || green_shift >=3D 32 || + blue_shift >=3D bits_per_pixel || blue_shift >=3D 32) { + vnc_client_error(vs); + return; + } + vs->client_pf.rmax =3D red_max ? red_max : 0xFF; vs->client_pf.rbits =3D ctpopl(red_max); vs->client_pf.rshift =3D red_shift; --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289238; cv=none; d=zohomail.com; s=zohoarc; b=X8+LECFQkwH1XdXUkiFW5V/kV4LTAZVM4ycOVkxsu+txPOHZvkJfsZEe+oEz2bhVeF7i8oA3aICv/JfrLJn14D5sehEozdavCsxdps2U/ZA4XX5FaVe6ML5uacOJrjCdQN7nu5Rr5fuwfXRjp0Zf0BWWKT7VGWOj0Qs6wrzXUGI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289238; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=frFHV5VMh2gEjRHqpI6AwiiG7GghoSraVhgp1HhS+bQ=; b=GrBGx46M7WceSE/z2EUvZrQI+cEshPlyiqxtzIDcID74xWnpKuRSBV8bPj7HOa63aoa+RqLN4hHvYS+ZjB28AzJcCklJvjvH0sK0Hkxvu6TrP3sdcR7ME7LSQf/uGiQ8aG91t7x6M8I7uJwW44b8AByTTD0KKUNujZ3HHXpGIs4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289238902710.1824756982036; Fri, 17 Jul 2026 04:53:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8F-0003nN-04; Fri, 17 Jul 2026 07:53:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8D-0003ms-LW for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8C-0003Pb-4P for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:29 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-610-ZPDYTL5pOvavuM34fq_Vsw-1; Fri, 17 Jul 2026 07:53:26 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 69BFB1955EA2 for ; Fri, 17 Jul 2026 11:53:25 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 44897D73 for ; Fri, 17 Jul 2026 11:53:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289207; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=frFHV5VMh2gEjRHqpI6AwiiG7GghoSraVhgp1HhS+bQ=; b=AMY35lrjoA+nhE3thudiKp298OiKDQ4u8hZYDBFKpEldJBP0TfaovcrMnbGNPuU2w0X/87 tS6TSDVbfXXtqsY+MMANbe3JRBRBM4WbAyu1LcBvHBeu0AEbUqDtPy5+8KOdt2CaObD7tf EaBX3goE+80MFR9wYMsIYZm/E77OvFg= X-MC-Unique: ZPDYTL5pOvavuM34fq_Vsw-1 X-Mimecast-MFC-AGG-ID: ZPDYTL5pOvavuM34fq_Vsw_1784289205 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:43 +0400 Subject: [GIT PULL 04/15] ui/vnc: use RFB wire types for client message handlers MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-4-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=5375; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=6LsiLUnImPepfr0mO2WpkW/ljNDW3QtTc4An2CVWOSw=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheZX/KorIc5JZJzUwY5k5IW7FTCDG3SWZDzK gyCc6Ey+FaJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmQAKCRDa6OEJdZac 5UN5D/4yPGLMYPH/1ZMD1Cq2qihAm7b/+zoUzaT4C0RyvsYW/9PKKFxnxsvr87gxJPDfLXlDWQ5 TLi7gsUOsqO2YAcBfPOnJWFMyrhGmfAkXZZVllNF+ndSp7twVU7Zq0USVdMsaCGLy6CTi0XbdgM qTjOsU/m9S8IfIcDr21blxiv+aIJ+wehGNxuJ1I+fz1qm1uTovHUyiYqmRFbc66nF+Cz9x4JuoI Qm5mAahH9pwFxK2t5mESkA+dPdDrPW6Ki5qEMVuHYgTnKJ23JAFci5lq44RtZXqkreCSsptJeMR xjReY4EQeaVYkOs/gq0bOkkjMAw/EPOuG0nXxF39VMly9HMVIo5f6DybhhRIM6rswo6CA14xwnR xK1sOhpuQaHsHqT1l2qmzEMVlFOooF7J8jZ3NtSTzWChTBdF8bK6DwvvRG3UyKikfTrbJQx31Vx NKlRTeHwlyIb09Awd/2pHrN4ZTSn8PojKpdPcJaWaugAMtN8Z+ukBVpfs7a6aOXM8DMCWdeHDP2 qCT+tL8It36JqbH6s9e1v8WBn14Enf6y6jR6yCrIR5mwRgCG9MxbPYY+S3g30aF8+XRXtVBzgca NumRVU6Y2PyfgfhbxsJGsp/XSINlZQlNpHVqnkW8gZBGmZEOts6iNcfyWHDtrPMT/lL2yA1EECl tvH+Jf0AHN+P3NA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289240560158500 Use exact-width unsigned types for the static functions that process RFB client messages, matching the types returned by read_u8(), read_u16(), and read_u32(): - set_pixel_format: uint8_t/uint16_t for pixel format fields - pointer_event: uint8_t button_mask, uint16_t x/y - key_event/ext_key_event: bool down, uint32_t sym/keycode - do_key_event: uint32_t sym - framebuffer_update_request: uint8_t incremental, uint16_t x/y/w/h Drop needless declarations. Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andre Lureau --- ui/vnc.c | 39 +++++++++++++++++---------------------- 1 file changed, 17 insertions(+), 22 deletions(-) diff --git a/ui/vnc.c b/ui/vnc.c index 9219f593d95..8d91cee4d9f 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -608,15 +608,7 @@ bool vnc_display_reload_certs(const char *id, Error **= errp) 3) resolutions > 1024 */ =20 -static int vnc_update_client(VncState *vs, int has_dirty); -static void vnc_disconnect_start(VncState *vs); - static void vnc_colordepth(VncState *vs); -static void framebuffer_update_request(VncState *vs, int incremental, - int x_position, int y_position, - int w, int h); -static void vnc_refresh(DisplayChangeListener *dcl); -static int vnc_refresh_server_surface(VncDisplay *vd); =20 static int vnc_width(VncDisplay *vd) { @@ -1763,7 +1755,8 @@ static void check_pointer_type_change(Notifier *notif= ier, void *data) vs->absolute =3D absolute; } =20 -static void pointer_event(VncState *vs, int button_mask, int x, int y) +static void pointer_event(VncState *vs, uint8_t button_mask, + uint16_t x, uint16_t y) { static uint32_t bmap[INPUT_BUTTON__MAX] =3D { [INPUT_BUTTON_LEFT] =3D 0x01, @@ -1841,7 +1834,7 @@ static void kbd_leds(Notifier *notifier, void *data) } } =20 -static void do_key_event(VncState *vs, int down, int keycode, int sym) +static void do_key_event(VncState *vs, int down, int keycode, uint32_t sym) { unsigned int lnx =3D qemu_input_key_number_to_linux(keycode); =20 @@ -2019,7 +2012,7 @@ static const char *code2name(int keycode) return QKeyCode_str(qemu_input_key_number_to_qcode(keycode)); } =20 -static void key_event(VncState *vs, int down, uint32_t sym) +static void key_event(VncState *vs, bool down, uint32_t sym) { int keycode; int lsym =3D sym; @@ -2034,8 +2027,8 @@ static void key_event(VncState *vs, int down, uint32_= t sym) do_key_event(vs, down, keycode, sym); } =20 -static void ext_key_event(VncState *vs, int down, - uint32_t sym, uint16_t keycode) +static void ext_key_event(VncState *vs, bool down, + uint32_t sym, uint32_t keycode) { /* if the user specifies a keyboard layout, always use it */ if (keyboard_layout) { @@ -2046,8 +2039,9 @@ static void ext_key_event(VncState *vs, int down, } } =20 -static void framebuffer_update_request(VncState *vs, int incremental, - int x, int y, int w, int h) +static void framebuffer_update_request(VncState *vs, uint8_t incremental, + uint16_t x, uint16_t y, + uint16_t w, uint16_t h) { if (incremental) { if (vs->update !=3D VNC_STATE_UPDATE_FORCE) { @@ -2250,10 +2244,11 @@ static void send_color_map(VncState *vs) vnc_unlock_output(vs); } =20 -static void set_pixel_format(VncState *vs, int bits_per_pixel, - int big_endian_flag, int true_color_flag, - int red_max, int green_max, int blue_max, - int red_shift, int green_shift, int blue_shif= t) +static void set_pixel_format(VncState *vs, uint8_t bits_per_pixel, + uint8_t big_endian_flag, uint8_t true_color_f= lag, + uint16_t red_max, uint16_t green_max, + uint16_t blue_max, uint8_t red_shift, + uint8_t green_shift, uint8_t blue_shift) { if (!true_color_flag) { /* Expose a reasonable default 256 color map */ @@ -2286,15 +2281,15 @@ static void set_pixel_format(VncState *vs, int bits= _per_pixel, vs->client_pf.rmax =3D red_max ? red_max : 0xFF; vs->client_pf.rbits =3D ctpopl(red_max); vs->client_pf.rshift =3D red_shift; - vs->client_pf.rmask =3D red_max << red_shift; + vs->client_pf.rmask =3D (uint32_t)red_max << red_shift; vs->client_pf.gmax =3D green_max ? green_max : 0xFF; vs->client_pf.gbits =3D ctpopl(green_max); vs->client_pf.gshift =3D green_shift; - vs->client_pf.gmask =3D green_max << green_shift; + vs->client_pf.gmask =3D (uint32_t)green_max << green_shift; vs->client_pf.bmax =3D blue_max ? blue_max : 0xFF; vs->client_pf.bbits =3D ctpopl(blue_max); vs->client_pf.bshift =3D blue_shift; - vs->client_pf.bmask =3D blue_max << blue_shift; + vs->client_pf.bmask =3D (uint32_t)blue_max << blue_shift; vs->client_pf.bits_per_pixel =3D bits_per_pixel; vs->client_pf.bytes_per_pixel =3D bits_per_pixel / 8; vs->client_pf.depth =3D bits_per_pixel =3D=3D 32 ? 24 : bits_per_pixel; --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289302; cv=none; d=zohomail.com; s=zohoarc; b=RUyBnHtbn/N0H/cYCr+jedrR2VR8c6SuaXI4X1qvXCR5Olkhl3n0nNH3kJrgLCz8i0ZmOM61vh3I6G2tZXAH4+DLItsDk70nA121SPwJUriO1K+yl0C1/93vnuIjgsldk3vrROLIo5EjMN8sFkJJAcJquU9zk7e4zRe8/9rOZDs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289302; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Q+d6T9+yJ9dU49+A0guqVDhBG9liq68F/Lzwj/pugL4=; b=SL/r7KKDiYJglfxpMOXEsmXeDKBFNoHDJYfjcs7YPFvZk0PUMQA8nLc065Y5vsFDur0llOO76gd8+zGvOVluwyzArQhLHb2lFOTwZdHMMvlUHNuYnvYMQlZscSMqEJuxQzMn++P7omos7uht0isRk5wSmEvMhAHwpSMchvOIdz0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289302171328.5690733426983; Fri, 17 Jul 2026 04:55:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8K-0003op-C8; Fri, 17 Jul 2026 07:53:36 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8I-0003ob-On for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:34 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8H-0003Pu-Cg for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:34 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-654-1oEFK3q5NCaHIKr5eOUItQ-1; Fri, 17 Jul 2026 07:53:31 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7E6B51955EA6 for ; Fri, 17 Jul 2026 11:53:30 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 978B230040BF for ; Fri, 17 Jul 2026 11:53:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289212; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Q+d6T9+yJ9dU49+A0guqVDhBG9liq68F/Lzwj/pugL4=; b=UVI5UKsaJ7X88c52xbQfu8DDXk3tlywrKctR4v9TaHnwLdSSrB/x43vMAZ4FYMkFe90gXm 10Dez1rwfsVnW1YTo02c2gv4Znc5/cnj+PgJRCpC1bdjXRDkVqarINMIQJyWnazx3Feh4o P0rtMaoJsrcoiHRbnr1wYu9rdS4TVr0= X-MC-Unique: 1oEFK3q5NCaHIKr5eOUItQ-1 X-Mimecast-MFC-AGG-ID: 1oEFK3q5NCaHIKr5eOUItQ_1784289210 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:44 +0400 Subject: [GIT PULL 05/15] ui/input-barrier: fix off-by-one in keycode bounds check MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-5-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1022; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=E1B0O3fJnedNADK1atu4Jy/3wDCbzWfL0PJwSeRCOAI=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheZA1l0n7OqMR0DOyjiVgdIQk1l937lZeiUs qgi4tnb+COJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmQAKCRDa6OEJdZac 5XfnD/9M0fuc6If8z+zhrnHjnT5fY9CvE52Nm7+oTVNSb8NDOkIfJHNIta1iQdepie2eFNh5iRv 1UHlutCoFg8vhj1pAKp7ARWPdho3wb9VyonUVbtvgDvMRNDL8EGtElpQqKpKQ8B76DTzlKmTkLy a6LhdQDaFW5uO1Yk7czoYvSpKA9yTjfpDvLwz4Kr5GV4V1iKaMW6DaHSaX6kkcUJiVVe/G0496U D5IKD35kZAMFDZCV7N+10lfxlUSvykiXmF5CojW1zzTRc/+1c/o+9Lcqvbrwh1UF2JskuFjQ3pv Fmr2MWKDvSnGGToGYtEvQYDgSmsIDCsZ45LwWh8gZsu/v7Z4FAXu7M3j6qSG0NMQtnPaqV6y8Mf TwP/aB+dkOpXx8uc6GUpomISXh/8WPymj/6oFOjUvA2Xn7c6AV6e7vjouJPWxQH+/SW3GikPiO7 eoJ/K02EJXtnxuYa37MHTkegIsuiKrsQ35jwgowsvfVhlMkJkE2VSYTk9bz4gdd2lQFKWzIhtwb f/HRhvyUTdoqx05eGUc+uTyIONvR1WdUj34lzXysUF3PovWCo545H7QyrEQlFvT1viwLAbWeGAe cI6i3BpRdjxOwihE1wEOfdKj7w9UKLKTtWpotWfWeP7xz+WNllkOfETmGXSgnu9gsLpqAP1j9cK B1SaB4DuNwllP1Q== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289302848158500 Use strict "<" to fix the off-by-one. Fixes: 6105683da35b ("ui: add an embedded Barrier client") Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3951 Reported-by: huntr bubble Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Laurent Vivier Signed-off-by: Marc-Andre Lureau --- ui/input-barrier.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ui/input-barrier.c b/ui/input-barrier.c index d07027114af..0a238d4010b 100644 --- a/ui/input-barrier.c +++ b/ui/input-barrier.c @@ -87,7 +87,7 @@ static kbd_layout_t *kbd_layout; static unsigned int input_barrier_to_linux(uint16_t keyid, uint16_t keycod= e) { /* keycode is optional, if it is not provided use keyid */ - if (keycode && keycode <=3D qemu_input_map_xorgkbd_to_linux_len) { + if (keycode && keycode < qemu_input_map_xorgkbd_to_linux_len) { return qemu_input_map_xorgkbd_to_linux[keycode]; } =20 --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289238; cv=none; d=zohomail.com; s=zohoarc; b=EJyOdIN1TupCEY0fmnNgQCRnIJPjP1Mn4wZ5nXDuSGht4ldj7OCuSKVigtAT13qGzCSAsKOTrfok1hV7LIt6jAqfZ88vnK9hK3pR91424+/XjrKRFY1ls9YXqzRCD69hYpBVOKd0VeC3ROAeUJkuJN5AOCWk+FwrJK07WFv8P7I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289238; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=1v2IJbKM5Oxjscr41lNHLZsQaoQQrBM5vp/Iq03XJl4=; b=k0kCEhmzfm4V2eCFeoJ/NSDQO79mZ9dRMSbCXzI+AqxHzShnALBCOBg4NZkTJXgsN7kiD9ujZnwPO0CU1lC1nIyJpqPtVSIMvohOjydVkkqLK3pCYtkk2Z+MVf0IP1pd9PLqPDz+Xw1ENZ3xTUDjKR9tb62QH/kAgZTKiVioiDE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289238606572.5837183845024; Fri, 17 Jul 2026 04:53:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8Q-0003yi-Fa; Fri, 17 Jul 2026 07:53:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8O-0003vd-Bx for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:40 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8M-0003QF-LA for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:40 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-692-18RIIaBxOrWPftmUs2gw6g-1; Fri, 17 Jul 2026 07:53:36 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B91CB180074B for ; Fri, 17 Jul 2026 11:53:35 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 9FB2C180029A for ; Fri, 17 Jul 2026 11:53:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289218; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1v2IJbKM5Oxjscr41lNHLZsQaoQQrBM5vp/Iq03XJl4=; b=OwIe1bhCz9Im6TUNoGLT9ZglQgOqLeAWM8ZkRWSbZD4M71iUCmQF167VcwasTx3SgtK+mH aIrPi34AezWWt1e828VyZ7reTtMCzzhrFZ8b4OwpJ/wOjQp5DO8TT0BKeukHIB6EXtSczS UaiTJ/dUaFmD3Uy+3ZmjH1+BRA54qDg= X-MC-Unique: 18RIIaBxOrWPftmUs2gw6g-1 X-Mimecast-MFC-AGG-ID: 18RIIaBxOrWPftmUs2gw6g_1784289216 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:45 +0400 Subject: [GIT PULL 06/15] ui/gtk: Narrow DMA-BUF critical section MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-6-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=5257; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=LqqMGY4JhJinImmIdRRHI4ZI7NgPKJAiKOMMBNgkfvQ=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWhea/nzAgbuT+z9Y0DZjeaLBr0yo5ldybCYPJ YxJLfGb1lKJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5TiUD/wLXVubCtcWE0LWygmg9SgUnuiVvTe3VmsymVTB8PcZVB5CjxPST4m+RZNW8Mv58IGNDlL IyfMZr17nIUznjbvV+UGcw2zRPPAk9DkXY7DoAjIdjwzMCJaiColaeIg5NsWKXFlwzAUm1w9jcS iyZlnloI5pYA0WchcdWL403kqcGrGK8C83UPQlZ2Si/Q4cY8qyYXuCiMipo2EcjqgMLDTW9AThY aWppE2WerqKwIr0wVqG6Md94gkvGYGPOQiHLdhNNiZeS2qutTyZqF8+JC3/nRqGWX3lW9PQmz/+ HoJQR37VgbsPhNBKMAnPxNw6GNW3ER7h05HCyY4qjrhmMscskvnjIvJm5QYfpNIV06R1ehyoTFN EqzLdx6W5gihfeAyT0w6oQhiFXfGwepsNyRi4Zgx60QjpdltqGsXFuteuUitWekP9eDjDBRLLoK 3tLYisU9eRgjtJODOMR8/gilDw4LwzmtB2dyURNSk7UfUX/tO8OZfK28puhfyQdVr26RO+24sxQ afC480X8eU47gwpRNlntHU0oJccDGTAIPvmO+jE2JNj2Ah/hRlLPuctEZO2ouPy+TLmh/mdFmfX bvhBeuBLhTON8Xtm+nUEyn9YVy3cE3hPc/wtINz1RupjV+EE2kSfpcMoNtcvLWrFU/BnUsZE2fk g04DEj3hWKpIsjw== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289240569158500 From: Akihiko Odaki Scanout operations need to be properly ordered to avoid tearing. The virtio specification allows the guest to use pageflip. With pageflip, the guest only modifies the invisible framebuffer while the host scans out the visible framebuffer. The guest may choose not to use pageflip to avoid its overhead, accepting the risk of tearing. ui/gtk performs the following procedure to flush a scanout: 1) Queue a draw event. 2) The draw event gets triggered. 3) Blit the guest framebuffer to the host framebuffer. When flushing a DMA-BUF scanout, ui/gtk blocks the device before 2) if possible and unblocks it after 3) to enforce proper ordering. However, blocking the device before 2) has two problems. First, it can leave the device blocked indefinitely because GTK sometimes decides to cancel 2) when the window is not visible for example. ui/gtk regularly repeats 1) as a workaround, but it is not applicable to GtkGLArea because it causes display corruption. Second, the behavior is inconsistent with the other types of scanout that leave the device unblocked between 1) and 2). To fix these problems, let ui/gtk block the device only when the queued draw event runs, immediately before 3). Blocking before that is unnecessary since ui/gtk does not access the framebuffer yet. If the guest does not use pageflip but instead updates the visible framebuffer directly, ui/gtk should not add the overhead of a pre-draw block. ui/gtk still blocks the device during 3) for DMA-BUF. Unlike the other scanout types, 3) can happen asynchronously with the device for a DMA-BUF, so ui/gtk needs to keep the visible guest framebuffer stable for the blit. With the problems fixed, the workaround to repeat 1) is no longer necessary and is removed. Signed-off-by: Akihiko Odaki Acked-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260628-gtk-v2-1-1e4839012f09@rsg.ci.i.u-tokyo.ac.jp> --- ui/gtk-egl.c | 6 ++---- ui/gtk-gl-area.c | 23 +---------------------- 2 files changed, 3 insertions(+), 26 deletions(-) diff --git a/ui/gtk-egl.c b/ui/gtk-egl.c index 7c5c9b2428c..adc81f34b1c 100644 --- a/ui/gtk-egl.c +++ b/ui/gtk-egl.c @@ -91,6 +91,7 @@ void gd_egl_draw(VirtualConsole *vc) } else { qemu_dmabuf_set_draw_submitted(dmabuf, false); } + qemu_console_hw_gl_block(vc->gfx.dcl.con, true); } #endif gd_egl_scanout_flush(&vc->gfx.dcl, 0, 0, vc->gfx.w, vc->gfx.h); @@ -405,14 +406,11 @@ void gd_egl_flush(DisplayChangeListener *dcl, =20 if (vc->gfx.guest_fb.dmabuf && !qemu_dmabuf_get_draw_submitted(vc->gfx.guest_fb.dmabuf)) { - qemu_console_hw_gl_block(vc->gfx.dcl.con, true); qemu_dmabuf_set_draw_submitted(vc->gfx.guest_fb.dmabuf, true); gtk_egl_set_scanout_mode(vc, true); - gtk_widget_queue_draw_area(area, x, y, w, h); - return; } =20 - gd_egl_scanout_flush(&vc->gfx.dcl, x, y, w, h); + gtk_widget_queue_draw_area(area, x, y, w, h); } =20 void gtk_egl_init(DisplayGLMode mode) diff --git a/ui/gtk-gl-area.c b/ui/gtk-gl-area.c index 23806b9d01b..29497019ee4 100644 --- a/ui/gtk-gl-area.c +++ b/ui/gtk-gl-area.c @@ -86,6 +86,7 @@ void gd_gl_area_draw(VirtualConsole *vc) } else { qemu_dmabuf_set_draw_submitted(dmabuf, false); } + qemu_console_hw_gl_block(vc->gfx.dcl.con, true); } #endif =20 @@ -163,27 +164,6 @@ void gd_gl_area_refresh(DisplayChangeListener *dcl) =20 gd_update_monitor_refresh_rate(vc, vc->window ? vc->window : vc->gfx.d= rawing_area); =20 - if (vc->gfx.guest_fb.dmabuf && - qemu_dmabuf_get_draw_submitted(vc->gfx.guest_fb.dmabuf)) { - /* - * gd_egl_refresh() calls gd_egl_draw() if a DMA-BUF draw has alre= ady - * been submitted, but this function does not call gd_gl_area_draw= () in - * such a case due to display corruption. - * - * Calling gd_gl_area_draw() is necessary to prevent a situation w= here - * there is a scheduled draw event but it won't happen bacause the= window - * is currently in inactive state (minimized or tabified). If draw= is not - * done for a long time, gl_block timeout and/or fence timeout (on= the - * guest) will happen eventually. - * - * However, it is found that calling gd_gl_area_draw() here causes= guest - * display corruption on a Wayland Compositor. The display corrupt= ion is - * more serious than the possible fence timeout so gd_gl_area_draw= () is - * omitted for now. - */ - return; - } - if (!vc->gfx.gls) { if (!gtk_widget_get_realized(vc->gfx.drawing_area)) { return; @@ -347,7 +327,6 @@ void gd_gl_area_scanout_flush(DisplayChangeListener *dc= l, =20 if (vc->gfx.guest_fb.dmabuf && !qemu_dmabuf_get_draw_submitted(vc->gfx.guest_fb.dmabuf)) { - qemu_console_hw_gl_block(vc->gfx.dcl.con, true); qemu_dmabuf_set_draw_submitted(vc->gfx.guest_fb.dmabuf, true); gtk_gl_area_set_scanout_mode(vc, true); } --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289279; cv=none; d=zohomail.com; s=zohoarc; b=eQtIh1SLPps1Zo4PF2O8lv/Ad6ZIs+UR+9hvvwYlLw7cr7imUnuOtvOV3cFHNd59t34ySj2n5ykLCAXPZMTSl/teW/9OgJvnMpRmNPhcql6zviTFqfdy1FmnOQrh+sYyvBtVwadLH3/4Vqk1BWiMhdb2hIrzAvOxtNw+/ilv4Lg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289279; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=bOkJZCc1dSzed9vvtL6uu5bHNkp3OjfHM14cHBb4Wf0=; b=A3jI4HC8NSsHm6rteUno9q3v+55i44evGVXIz8s0F+wucG4hDJVWOsb4L/5V8r/7Togknc4/pq97atAzXwhJ9XRk5fsKVvBkuEtgNyvlBxw3yGfeuNln0p9ZUUdbq8S2V7ASiw94rJOSQHFFLWmgjIEylSuX/usWp8dRZpX56q0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289279903765.475305516584; Fri, 17 Jul 2026 04:54:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8Y-0004RV-Bx; Fri, 17 Jul 2026 07:53:50 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8U-0004O3-LT for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:46 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8S-0003Qq-9N for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:46 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-310-VA3DtHE5My6yadTc1EaK5A-1; Fri, 17 Jul 2026 07:53:42 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4D0B91800667 for ; Fri, 17 Jul 2026 11:53:41 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 38C511955D86 for ; Fri, 17 Jul 2026 11:53:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289223; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=bOkJZCc1dSzed9vvtL6uu5bHNkp3OjfHM14cHBb4Wf0=; b=LJnSgP5q4DnIVaolqSmEDK8klR8MlFFFCTjfpHjP0ko0h4StbQ4B8WiLrzmlj4nvkiaWDT H8KrJMkU9Mh5K2UvRf6XUyfUP0H6Hk6+8thMVmhlZE0u5L2XHW1FBHxy1Oka+GY9O5576e OlJcu/z/pd2WWPFYKpWufhpndMq+BU8= X-MC-Unique: VA3DtHE5My6yadTc1EaK5A-1 X-Mimecast-MFC-AGG-ID: VA3DtHE5My6yadTc1EaK5A_1784289221 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:46 +0400 Subject: [GIT PULL 07/15] ui/vnc: fix out-of-bounds write in lossy refresh dirty marking MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-7-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2294; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=CxVMW5HXmXT2p59JNqgnfulfZZMYD+aakrFZing6FaY=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheaVS9XN+hg+MOJZs854MOuV5S8CHIXuunEM bzyVLUzxGmJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5dtKD/9SKs4FzrBIf3viLrksC3d5RX7mHfyxMpVXVHmmM6nTC+Kzg4NqCk0SkQ/2tlX2k/fADT0 33UxmzmSZuP3vJWpnNtVfT0bsk8s58+fF3XnMFjKlUcemySclVJt76gJ0cJEx+wMC+rDJC3Z2yA kH8bWCJz4h2dKTi1eVMutawx84Ya30wHktSvbmZbYtKaviwp8R8r36Q7WfvrAVV9JJnByfq+96S AFyhPoHMTTyzTZnQXsJOoSbyRg8ZfTJVVD89VZTGR+R/TqSkrWcYsFwxLyKh9MKUTEVu60Oh822 t6HC7X7qwjjgQw85qXZD8CyhscsfGkf/KfypQwyCkYN3ncHWj89rT8vJUjKiKaXTBPwKCd7ghP1 vOGd8PInTT47qGtBOaERxmpRegGM6UjVc2GBmdu1CvvrbY/t7k8QTuVryidrB/3eWBUU56c32MO aGESMZkVgAIaL5txZfugckEMXOPZYfHEqn6FSxFN2JTWvqIlmrIStYiKHnrTpG1Nly5Dg7/mNte VWH0Z730S3h8YP3wwh6jq9erNhgrIwqIv6h6fh03MC3r1fIqTFB1XogjTAcWEgg//477yXw7EWS LOP0Lhl7aRSyblQCc6Ow77exkB6mPoxXjew+An1USfdY4uhn/eza4oIe9z5iyELLrW6ynRDbkg3 IoSrCN49UbSHHOQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289280902158500 vnc_refresh_lossy_rect() marks a full VNC_STAT_RECT (64) rows of the dirty bitmap when refreshing a lossy tile. When the display height is not a multiple of VNC_STAT_RECT, the last tile row is a partial tile and the loop writes past the end of vs->dirty[VNC_MAX_HEIGHT]. For example, with a 2160-pixel-high display (VNC_MAX_HEIGHT), the last stat tile starts at y=3D2112. The unconditional 64-row loop writes rows 2112..2175, overflowing 16 rows (640 bytes) past the dirty bitmap into subsequent VncState fields. Fix by passing the effective display height into vnc_refresh_lossy_rect() and clamping the inner loop. Fixes: CVE-2026-61475 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3935 Reported-by: "Vulnerability Report" Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andre Lureau --- ui/vnc.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/ui/vnc.c b/ui/vnc.c index 8d91cee4d9f..c957731877f 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -3000,18 +3000,18 @@ void vnc_sent_lossy_rect(VncWorker *worker, int x, = int y, int w, int h) } } =20 -static int vnc_refresh_lossy_rect(VncDisplay *vd, int x, int y) +static int vnc_refresh_lossy_rect(VncDisplay *vd, int x, int y, + int height) { VncState *vs; int sty =3D y / VNC_STAT_RECT; int stx =3D x / VNC_STAT_RECT; int has_dirty =3D 0; - int height =3D MIN(pixman_image_get_height(vd->guest.fb), - pixman_image_get_height(vd->server)); int rows; =20 y =3D QEMU_ALIGN_DOWN(y, VNC_STAT_RECT); x =3D QEMU_ALIGN_DOWN(x, VNC_STAT_RECT); + rows =3D MIN(VNC_STAT_RECT, height - y); =20 rows =3D MIN(VNC_STAT_RECT, height - y); if (rows <=3D 0) { @@ -3083,7 +3083,7 @@ static int vnc_update_stats(VncDisplay *vd, struct t= imeval * tv) =20 if (timercmp(&res, &VNC_REFRESH_LOSSY, >)) { rect->freq =3D 0; - has_dirty +=3D vnc_refresh_lossy_rect(vd, x, y); + has_dirty +=3D vnc_refresh_lossy_rect(vd, x, y, height); memset(rect->times, 0, sizeof (rect->times)); continue ; } --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289251; cv=none; d=zohomail.com; s=zohoarc; b=SJmPrKMNIgVg3905wxwNUYqWHYYn93pyLIeEHtSWfOQUEICQeK/Gmy+fpjsSnmkRBoOsloAqzCQ1jj2g+cHkBAytoJ0o0JtSs6Kg+7dt65v2OZxjilC0ecXtRTF+d5OCVWboH3cmNOtveYr9ivZwEJJYGKmMXGu1hD6tXc0Hfv0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289251; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=HTpzX+M6eo5BMfGMYdfxPXrnNBGT5NtLbqGrbPxJzHs=; b=Oa8lpgUxt8Zn1dg7Jwi39Bqnm0hH5wv/gdJGfzangBm2RTE5WsPWEP7KFY4vNw921gtHcUaDoNPL/K6vkI2QzprX3xk9inB8oAkYScAFCuONLRtAjh5HjsVII9XwTIT3EBY4WdJ3p0HhRI/YGURd+DqGlsNdkqOD4DVCQmeOga8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178428925151874.26416200898223; Fri, 17 Jul 2026 04:54:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8c-0004gD-U3; Fri, 17 Jul 2026 07:53:54 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8b-0004bA-3P for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:53 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8Z-0003Rn-JP for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:52 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-12-tlmDR1YJN46gvEF_PMjSgA-1; Fri, 17 Jul 2026 07:53:47 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6546C1954B27 for ; Fri, 17 Jul 2026 11:53:46 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 52E211956049 for ; Fri, 17 Jul 2026 11:53:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289228; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=HTpzX+M6eo5BMfGMYdfxPXrnNBGT5NtLbqGrbPxJzHs=; b=h+UQbkiVr1LCBy9ZTaZdTexBIxvWAqZGzUIqGfLNwbpNpT+jH2D8TZBmDJEtFc6iQnyngc YxL080o9z/E5vkS//hPqc57ycvwaNnOiXa2SOf7h7iORzPy2l93oKKx/WJqnXYxGu4ol0P Fsf9GGyODneiA+xPp0MV7S1iU12MtTY= X-MC-Unique: tlmDR1YJN46gvEF_PMjSgA-1 X-Mimecast-MFC-AGG-ID: tlmDR1YJN46gvEF_PMjSgA_1784289226 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:47 +0400 Subject: [GIT PULL 08/15] ui/vnc: validate SetPixelFormat field ranges MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-8-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1306; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=FG5CL8eAqS0Q4JiU5TvJg/DwgxeKGJI/nGnE2BmZm+o=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheaA4CzmtI7edy5sVYIdkpLCvV9uXxtiPq3n tcnWSs1xWOJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5TrQD/wMFpp9DEifohnXpmLGd8xg7Pl56Ny4JicmO6tK9TMrR75GV9ZNe7RVcvSyPVqbFaybW3O tk2W7FGdt7fZyMEA+ot8FWlDJ/dQeNUf5a51ZIgUK5dwNAoqYXwGjLzukUejJtO8p6zzzYZAGp3 DM9uxWgsLP8iz3MLHd/pyEPtJOkhF0Zp7kTJytus/bDdH3NDb4HxVexe0ZP/4TiVtSn4KSa8BzL ORP8y+SLGxA4kz0xE9l4YLCY4LkMC1Lf3/OmmAXWu9wT3OC8OpUpfuOAknjMrHzUXFqzSNCWCSr 1qK0KniLAEe6l8zfHX1ll34D7kKhrD8bJ6TE3N6V4ldMnef1fQmhspxjXHiPx++efhjEdQvgJ4H Af3rTxMo6aeSoISRx7QEvlDfQqvID3d25X2DNVNHiuutcB9/engI0L25oc29kJeZBtWVtwnx1lW r0lSEDaqcBiYE9NGTMnpMqB/1bPlxXM5Uj9G/w5PFaSkS8emVOBU4wzjsX1FJGMSExWkItsIH9k QJ8DwtrDNzXdKWcTCeVs/W9A8l3ueryzXo2yJ/d+nYr2cYOyTiyh4vSsstAYxRzIN5vRIUFjc7r 3RqHb9fkFDLVdluQMTEHa0XIrR4RebMc7CiL8qzltzuvtAawmX0Tw30WskCNkuBch+wjur4AD0l X51qZCzgK7cJlnA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289252590158500 The VNC SetPixelFormat message carries red/green/blue_max as 16-bit values, but PixelFormat stores them as uint8_t. A client sending a max value above 255 (e.g. 0x0100) passes the existing non-zero check but silently truncates to 0 on assignment, leading to a division by zero in the Tight PNG palette path. Add explicit range checks if any channel max exceeds UINT8_MAX. Fixes: CVE-2026-15578 Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3976 Reported-by: dong ling Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Marc-Andre Lureau --- ui/vnc.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/ui/vnc.c b/ui/vnc.c index c957731877f..24aa40f7308 100644 --- a/ui/vnc.c +++ b/ui/vnc.c @@ -2271,6 +2271,11 @@ static void set_pixel_format(VncState *vs, uint8_t b= its_per_pixel, return; } =20 + if (red_max > UINT8_MAX || green_max > UINT8_MAX || blue_max > UINT8_M= AX) { + vnc_client_error(vs); + return; + } + if (red_shift >=3D bits_per_pixel || red_shift >=3D 32 || green_shift >=3D bits_per_pixel || green_shift >=3D 32 || blue_shift >=3D bits_per_pixel || blue_shift >=3D 32) { --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289251; cv=none; d=zohomail.com; s=zohoarc; b=PIoTQAoFfFAKVlNqSzKZQQMTIQazU39UChAHGWPhIkwVknzeqBNhmZxaUfirrUzgcYqTkbqWY91xvWtQ+iSV0kF+UbwUWjVLfYOThH5msLqYMZP3YMVQvmOum8xpORPPZdsjLNwQWVwuZyYBRcO3kWpxMsfioY74qGi5nnlyj3Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289251; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Py9sueUcvDOLQV1YacJm2IgmkQ8EMFzR3H2U3/ovunw=; b=PbCYFfZjvK0XRbh/apA+xXeCR6zQ3HNSXbn8yZCM8gM2OPH/9BzaZ2KtmMIjN0rguWtWUNLgaVa+VoGBpwkZPXi2DcvKsA4dEXEBF5o/DF68c6wZ/WtSiXSFA3zCCLzCjiI4CZf8N/slCCv2wZ4ipVljJ6Sl+B1Py0vTgbmcnHU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289251502898.8456048452913; Fri, 17 Jul 2026 04:54:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8f-0004jC-FS; Fri, 17 Jul 2026 07:53:57 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8d-0004ga-Vv for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:56 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8c-0003SG-IS for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:53:55 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-59-5v2iWF7INrO5QG1qtfB5mg-1; Fri, 17 Jul 2026 07:53:52 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D029918007D2 for ; Fri, 17 Jul 2026 11:53:51 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id EB139180034C for ; Fri, 17 Jul 2026 11:53:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289233; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Py9sueUcvDOLQV1YacJm2IgmkQ8EMFzR3H2U3/ovunw=; b=C7WTv8h8Vt48TINmFX3GzeuKzubnzk6IbF/zP6XNGssEMqgXVrwfs39RQ3SPrS43z/H1lt QuCEK7JtNkURRwBEHXgpZQgvk4RCYWoqYMWpog5rbHPDIWJx/u1bcWs1w+uygrFy7GZF5s GtiWvrM37jomfDM2pStYSDACqw4URhE= X-MC-Unique: 5v2iWF7INrO5QG1qtfB5mg-1 X-Mimecast-MFC-AGG-ID: 5v2iWF7INrO5QG1qtfB5mg_1784289231 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:48 +0400 Subject: [GIT PULL 09/15] hw/display/virtio-gpu: fix dmabuf_fd leak on remap failure MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-9-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1460; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=vLdcAxZ8xQPI4i6TVMAkpWJIUU2DGKECrUR33XNoTng=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheaFZEso9QZyfka6/XhTGozpxaQPPZWLQHUi WWQEDrG0l2JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5cajD/426qHQvqN5zQR2MS4QM5++TiVQRLbhVPhGlcK9nSrCdE3CPx0MgrB0/JvjbCJUGrMBfQ6 dLukjoHmQtIHBPfGW9ltvf3oXvY/nYxL81P5WUcsUy9SWqu6qLGt6TRQsSPOxQA7dNZeGbq9AB8 /JX8evXFyBjvBfK1KWxqKmCNywTWk7QRvaZXGKSPCLbuBGcyn7h8OnMVnmCVEgsYGQzB8MtuV1F ddKETfncajLha/fzrE34kPbrdKANcT3TNZe4y1T5BTXCiBDJPouzCvGmUOmaJFj/cvmW2aTICTL IJNbYeCmAaTKmGUCzlVbE4bpn9L0DP4BFEMIeAtQeBDxwW1Vd9bNF++cKjIJJF8nr1bwY2RTZGj efgTVgWA7sRA+sKZs4traJdhGh9bQ37MzHnxjgQCefxhr9FQCnCMkCQvVdbXHpGwlFjsj7oLuwv +SJUwi8mS2LcSC9jv8yn1UhI1uoVeflB2d3fYJnfO9tIa17oV2suU7tFLLILdF+NsDUghN/6RYC oC11Q1ydlyGnqRfB0KQfp6BJqTorFeCEdYmJ4dbgqrl9wyPfhT9LAH3fehgN5Mma0vE28iomvi3 Tdnu/JOq+Xj/Hrxt5uQwuG50bb5VsL7iEenLHFpPmI2GUMZ1cwx9Eu1/iJzjqPvblughFM1t8wb gxNEv99lVTTdufA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289252593158500 When virtio_gpu_create_udmabuf() succeeds but virtio_gpu_remap_udmabuf() fails (mmap returns MAP_FAILED), virtio_gpu_init_udmabuf() returns early without closing the dmabuf fd. Since res->blob is never set in this path, later cleanup via virtio_gpu_cleanup_mapping() skips virtio_gpu_fini_udmabuf() entirely, leaking the file descriptor. Call virtio_gpu_destroy_udmabuf() before the early return to close the fd. This function already handles partial state correctly: it skips the munmap when res->remapped is NULL and closes the fd when res->dmabuf_fd >=3D 0. Fixes: 9b60cdf98723 ("virtio-gpu: Add udmabuf helpers") Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Dmitry Osipenko Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau --- hw/display/virtio-gpu-udmabuf.c | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/display/virtio-gpu-udmabuf.c b/hw/display/virtio-gpu-udmabu= f.c index d5ac1cfca0e..5f08c855dde 100644 --- a/hw/display/virtio-gpu-udmabuf.c +++ b/hw/display/virtio-gpu-udmabuf.c @@ -143,6 +143,7 @@ void virtio_gpu_init_udmabuf(struct virtio_gpu_simple_r= esource *res) } virtio_gpu_remap_udmabuf(res); if (!res->remapped) { + virtio_gpu_destroy_udmabuf(res); return; } pdata =3D res->remapped; --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289271; cv=none; d=zohomail.com; s=zohoarc; b=EthAVH6WQ6fpDyxZw6x4GPeU19AYo7eEQ3GltArXpD/BVnnNztc7NQOPucNXetUOELLVJKnSINve+vo4MTyuF12ToVwB/nJuILIWabk12YIbnnHfpk+qrrh6FUUbu98+fHHgI/Z2RN7mSJUagFH/vDkGnLcNkIqShdbjTWnkJR4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289271; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=u/JocELUzciLrI2R+2g24aN1QWMe8pYZXVY3rWZQaXc=; b=mFxtT077mE9g2TjAiym7NJFWTmzlW7AGC9yH4EDjYlntQ550f2tX9mkTVS5F+DTVAe5D04mMoX4B4XmOOp4QuDNH0eJI6Fo0s66xWIavNjU+iRp+7TFbnayIr9HVJVESzoatsNAVKRugL+yxGfZ1WiD1BRPPX4w2Ft+emY8crYA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289271873342.2453842076185; Fri, 17 Jul 2026 04:54:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8o-0004qD-Ba; Fri, 17 Jul 2026 07:54:06 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8j-0004oy-2t for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:01 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8h-0003SU-E1 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:00 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-62-pJVjfXucOOeYH-kWZGdU7Q-1; Fri, 17 Jul 2026 07:53:57 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B297C180075F for ; Fri, 17 Jul 2026 11:53:56 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id A7CB51955D86 for ; Fri, 17 Jul 2026 11:53:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289238; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=u/JocELUzciLrI2R+2g24aN1QWMe8pYZXVY3rWZQaXc=; b=cQhAuqKsr5JBPEYBasqk9Vz7xaArFpaJgmQjBm8cE5FLXJ4jOZ6+lrVxa6LKJAyDiZ8uSi z399/Ccs1hXcyjBAmkBCoezEIHVDyhAMs0X/le4r5tyBYP/rMDXMfCJaBfm4hDo6mRUyYV NN7aCoEnYKGmuUwyOD3KZrKM3b1Ss6U= X-MC-Unique: pJVjfXucOOeYH-kWZGdU7Q-1 X-Mimecast-MFC-AGG-ID: pJVjfXucOOeYH-kWZGdU7Q_1784289236 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:49 +0400 Subject: [GIT PULL 10/15] hw/display/qxl: fix TOCTOU in cursor chunk data_size handling MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-10-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=5603; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=GpIUqifl/gyolM0MgyVL0mom4t/4c7mPXqLdbQ0eOAs=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheayjWEFXZK9oBDZ+zk+DJ1F8tKetKCULl5o SG77hA4w1qJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5VTeEACByQei7qBPYuTnmmBuTNGOyrIrhE7B2TaC9NtmgjxCBv5MqRzjMenwnv/z5712gfKW9Q7 NQhEPae+zZJWezDMYEaKhKqiDI/VbeB47M21xkFaCS8OUR0jV9vqcJ5Zs5rz6KfJRihQhrxXbuI Cv5VGobNLRQMY659NFZIbGVeMtPUZwHY0quc0HhgvkIBHJq+qDVF6S3ENrnJsPZYpWDRO/gZS33 PSknwlVpO/k7xWw1svibOnJDr/ocfY8FKx6Zw1+RDVg0jKu5eX0yUGeHWUDD/VvkMlMqso5FlN1 Y3IjDXvo49OBNuEFrrhvhnkS1ZNqu9rboG9oDcCjp7KCJlZ13KEELSN52jZi20C4YRU0A4R6AIa hmhVeWCluhhbh8JHvzFYOO3pCgtMvbkqkHViYxSGBKtuO7T4RZFqRM5iM6T/igAfKqeGyK0m63b 6Gp9PrLxmFv4Ph0LuAoCiO5Hvyt5R5hCUcr7lvk7yKkD+2+7bWjnH0s3TWkJR0Q69zBeGh93Cql l2IYz70P0oZM/+nQTHYbE84j5L//7/j2cZYNIWsokxA63ftI/PwY0bxWIRzlL7x/N6OARigaxzY uYDiWH41tpzONVbG/wrZ4aFCCykQrQcYh8+8WryXdoqurYdYVm9PgedacuT1410u+gkfeiPfyBv 7FMZdns1o5aEQqQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289272778158500 Snapshot chunk.data_size into a host-local variable before passing it to qxl_phys2virt() for validation, and pass it through qxl_cursor() and qxl_unpack_chunks() so that no subsequent code re-reads the field. Without this, a racing vCPU can inflate data_size between the qxl_phys2virt() validation and the memcpy in qxl_unpack_chunks(), causing a source read past the validated region. In practice the read stays within the guest's own VRAM mmap, so the impact is limited. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3757 Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reported-by: Feifan Qian Signed-off-by: Marc-Andre Lureau --- hw/display/qxl-render.c | 28 +++++++++++++++++----------- 1 file changed, 17 insertions(+), 11 deletions(-) diff --git a/hw/display/qxl-render.c b/hw/display/qxl-render.c index 3bf634ee059..4799c9e8bef 100644 --- a/hw/display/qxl-render.c +++ b/hw/display/qxl-render.c @@ -217,7 +217,8 @@ void qxl_render_update_area_done(PCIQXLDevice *qxl, QXL= Cookie *cookie) } =20 static void qxl_unpack_chunks(void *dest, size_t size, PCIQXLDevice *qxl, - QXLDataChunk *chunk, uint32_t group_id) + QXLDataChunk *chunk, uint32_t group_id, + uint32_t chunk_data_size) { uint32_t max_chunks =3D 32; size_t offset =3D 0; @@ -225,22 +226,21 @@ static void qxl_unpack_chunks(void *dest, size_t size= , PCIQXLDevice *qxl, QXLPHYSICAL next_chunk_phys =3D 0; =20 for (;;) { - bytes =3D MIN(size - offset, chunk->data_size); + bytes =3D MIN(size - offset, chunk_data_size); memcpy(dest + offset, chunk->data, bytes); offset +=3D bytes; if (offset =3D=3D size) { return; } next_chunk_phys =3D chunk->next_chunk; - /* fist time, only get the next chunk's data size */ chunk =3D qxl_phys2virt(qxl, next_chunk_phys, group_id, sizeof(QXLDataChunk)); if (!chunk) { return; } - /* second time, check data size and get data */ + chunk_data_size =3D chunk->data_size; chunk =3D qxl_phys2virt(qxl, next_chunk_phys, group_id, - sizeof(QXLDataChunk) + chunk->data_size); + sizeof(QXLDataChunk) + chunk_data_size); if (!chunk) { return; } @@ -252,7 +252,7 @@ static void qxl_unpack_chunks(void *dest, size_t size, = PCIQXLDevice *qxl, } =20 static QEMUCursor *qxl_cursor(PCIQXLDevice *qxl, QXLCursor *cursor, - uint32_t group_id) + uint32_t group_id, uint32_t chunk_data_size) { QEMUCursor *c; uint8_t *and_mask, *xor_mask; @@ -272,11 +272,11 @@ static QEMUCursor *qxl_cursor(PCIQXLDevice *qxl, QXLC= ursor *cursor, case SPICE_CURSOR_TYPE_MONO: /* Assume that the full cursor is available in a single chunk. */ size =3D 2 * cursor_get_mono_bpl(c) * c->height; - if (size !=3D cursor->data_size || cursor->chunk.data_size < size)= { + if (size !=3D cursor->data_size || chunk_data_size < size) { qxl_set_guest_bug(qxl, "%s: bad monochrome cursor %ux%u" " data_size %u chunk_size %u", __func__, c->width, c->height, - cursor->data_size, cursor->chunk.data_size); + cursor->data_size, chunk_data_size); goto fail; } and_mask =3D cursor->chunk.data; @@ -288,7 +288,8 @@ static QEMUCursor *qxl_cursor(PCIQXLDevice *qxl, QXLCur= sor *cursor, break; case SPICE_CURSOR_TYPE_ALPHA: size =3D sizeof(uint32_t) * c->width * c->height; - qxl_unpack_chunks(c->data, size, qxl, &cursor->chunk, group_id); + qxl_unpack_chunks(c->data, size, qxl, &cursor->chunk, group_id, + chunk_data_size); if (qxl->debug > 2) { cursor_print_ascii_art(c, "qxl/alpha"); } @@ -325,19 +326,23 @@ int qxl_render_cursor(PCIQXLDevice *qxl, QXLCommandEx= t *ext) } switch (cmd->type) { case QXL_CURSOR_SET: + { + uint32_t chunk_data_size; + /* First read the QXLCursor to get QXLDataChunk::data_size ... */ cursor =3D qxl_phys2virt(qxl, cmd->u.set.shape, ext->group_id, sizeof(QXLCursor)); if (!cursor) { return 1; } + chunk_data_size =3D cursor->chunk.data_size; /* Then read including the chunked data following QXLCursor. */ cursor =3D qxl_phys2virt(qxl, cmd->u.set.shape, ext->group_id, - sizeof(QXLCursor) + cursor->chunk.data_size= ); + sizeof(QXLCursor) + chunk_data_size); if (!cursor) { return 1; } - c =3D qxl_cursor(qxl, cursor, ext->group_id); + c =3D qxl_cursor(qxl, cursor, ext->group_id, chunk_data_size); if (c =3D=3D NULL) { c =3D cursor_builtin_left_ptr(); } @@ -351,6 +356,7 @@ int qxl_render_cursor(PCIQXLDevice *qxl, QXLCommandExt = *ext) qemu_mutex_unlock(&qxl->ssd.lock); qemu_bh_schedule(qxl->ssd.cursor_bh); break; + } case QXL_CURSOR_MOVE: qemu_mutex_lock(&qxl->ssd.lock); qxl->ssd.mouse_x =3D cmd->u.position.x; --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289272; cv=none; d=zohomail.com; s=zohoarc; b=HxaGBBQaK/TKvI9iT/Toj13elzs0OnqnGhXGmnuKTVf9F92/SLV+HCoN8+DFxsaVDPGr/vGCX3EfxrONA8+Inr54U2Yui9wVKZxzgWnTgQHS9ICuJzA/tFQ2Dge2ktl6MFN4J/oFPg/bPp1XrX8Fu6Pvd1RP7/MEY0PW3LTpOa8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289272; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=36RJqVPwaBMvjLN3VZbKH8Wswuy8bro5HEmKr61RjUo=; b=ndnW9ArEW7LFKlxYQLEZSQWoIkT9HAc/yP2WxkjxneCNVArsOkOlMGRVpDL6VfKW6itN/ZiKiZ2wYEeW9pXw+LxWGPdOOpY56wKlu91NezBWshYvYgnmrFIy0e4s5bawk+BaocFJdRJlVtebk/G4Krxn20hm5vaBJNFOMNUdzCY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289272986697.745489283048; Fri, 17 Jul 2026 04:54:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8s-00053C-48; Fri, 17 Jul 2026 07:54:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8q-00050y-Cx for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:08 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8o-0003Sg-O8 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:08 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-121-cLTfsJ3fOKyVdgwaNlhdDA-1; Fri, 17 Jul 2026 07:54:03 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 484ED1800750 for ; Fri, 17 Jul 2026 11:54:02 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0C28B30040BF for ; Fri, 17 Jul 2026 11:54:00 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289244; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=36RJqVPwaBMvjLN3VZbKH8Wswuy8bro5HEmKr61RjUo=; b=AdO2bgy7C6ktbOLfX5n0S6++l6/OueReqX79DK+DtK9cIkRidlYGg1tGRXXC+ZFuw4kHMD mTqfMdGbVp1ZjcCywDoztyjBAdOMbua93Kr/2sTXZatHgt15uCcBE59MMbX3XV8egzLn8w s+30E3G5rZM48dt5MjIozXG7mDiyBjI= X-MC-Unique: cLTfsJ3fOKyVdgwaNlhdDA-1 X-Mimecast-MFC-AGG-ID: cLTfsJ3fOKyVdgwaNlhdDA_1784289242 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:50 +0400 Subject: [GIT PULL 11/15] hw/display/virtio-gpu: validate stride against width on scanout MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-11-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2368; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=/2k1yLXrr0iajI/tlLhcu7f0CvyuxjSOgEJVPdgkS2Y=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWhea7rqZfR4+V/5+jozm1ihzOwvOot3mciRki dxJYpRbnoeJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5QgoD/97Hx/fysWjY8YhuRos+bE57XsR9yQvhgy6YjG6exiuFENj4A1iDvZLb+3vvghIxhVxQ+J yL5lpHYpltfK1+J/XGqIiKPF8bHvivkmYpm9dzFyHJ5GHj/qRcDngj31gjA7IVc+hPiI7/4s7Xk U/aJVpPs2ljjxLXLoVI2dK0aitfApDTKrtTPhziRuY7UEhuh+9KxTtjBiBSlUl+1/ADvalyCajC x6OfSvh1UJYl2OmZRj3aaAooMAQGxjFwMqPa0TjjXkUAxpQXcLLb6bX43J6o6N/f6eShBtQHFOD 0GET53bpqfh9vch3+Uyqo7kTu2r2IdYbqRaYO0qzjfKYL5NIGRgMhNdl38lOqMgfxJ0PPS+DQnn GJmiY4zGisEQCT2fzzH38/81ffe6aHObBfbFyE8wU3311tMblsIdM8Pwa4dW4y/QlUQ+WTn9vJS +tpcaEYQp9aSI0FOEH6pL1Uq66O7a8GXCvowluo7byyZA2CLLRI0sVPgfBDJ8rq5SQv8EmM7kvh FDYp2If286r8NcsvNXEKScChXLNo0DhafvlaU2dW3kqAvDV7OMxuxKT2vfXaqq08pCeadStwJi9 e5WhGEjJDE72f7Ho/tKrS80cfs9L1HppCwOAwT0YrDuqNlH7e7/n9sTXA3NxS1gHALrfatHC6Bb gJVIaHk1ChZpdsA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289274725158501 Validate that the framebuffer stride is at least width * bytes_per_pixel in both virtio_gpu_scanout_blob_to_fb() and virtio_gpu_do_set_scanout(). A guest can set a very small stride while using a large width. The total size check (offset + stride * height <=3D blob_size) passes because stride * height is small, but pixman reads width * bytes_per_pixel per row, causing heap OOB reads. The leaked data is rendered to the host display. The check is added in virtio_gpu_do_set_scanout() to cover all paths: blob scanout, non-blob scanout and migration post_load. The additional early check in virtio_gpu_scanout_blob_to_fb() rejects invalid blob configurations early. Fixes: CVE-2026-63109 Fixes: 7b5574225429 ("hw/display: check frame buffer can hold blob") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3989 Reported-by: Tristan @TristanInSec Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau --- hw/display/virtio-gpu.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 88526051a99..e00fb6effa5 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -646,6 +646,14 @@ static bool virtio_gpu_do_set_scanout(VirtIOGPU *g, return false; } =20 + if (fb->stride < (uint64_t)fb->width * fb->bytes_pp) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: stride %u too small for width %u at %u bpp\n", + __func__, fb->stride, fb->width, fb->bytes_pp); + *error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return false; + } + g->parent_obj.enable =3D 1; =20 if (res->blob) { @@ -753,6 +761,14 @@ bool virtio_gpu_scanout_blob_to_fb(struct virtio_gpu_f= ramebuffer *fb, fb->width =3D ss->width; fb->height =3D ss->height; fb->stride =3D ss->strides[0]; + + if (fb->stride < (uint64_t)fb->width * fb->bytes_pp) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: stride %u too small for width %u at %u bpp\n", + __func__, fb->stride, fb->width, fb->bytes_pp); + return false; + } + fb->offset =3D ss->offsets[0] + ss->r.x * fb->bytes_pp + ss->r.y * fb-= >stride; =20 fbend =3D fb->offset; --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289302; cv=none; d=zohomail.com; s=zohoarc; b=F50x3zH0eYlHlZl7G8h8dQIrAlwETUgN+/om3In4Gz2bJdXjyxM9N89xqcmDdDel74u7p6UaOdaU8HvwGDwp8GctP7G2Z2b3SyVuywUfNzBOuQyNkr2GzFvA8I4hsxRtcUn6mAIQI/ONuBu8CTAzxZ0k74/UUXhW/WoIqaSYWhQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289302; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=G2DjTqkkGv9hx92D0WNYid3pXflD4YCT9E+5cXBSj1I=; b=FIk4OALd0QmWXMFVZsgOB06GZ4AkNnw+Lp9e40BpAh5ktnt/vh8iMdUCW/iR7stMN53oHFGwVlHfg7ZcmB02ZpbHYUKCh+dJjVOAqAkoQml+z6niUE06h39CP4jWL51PjMv7CCcA2vt8DvNj0UmGtvh1lRPHAgkyzkRImxpfAXE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289302504389.59834032605875; Fri, 17 Jul 2026 04:55:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh8x-0005Tf-Fd; Fri, 17 Jul 2026 07:54:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8u-0005Eb-Q4 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:13 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8s-0003Sy-VB for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:12 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-574-Hr_KGsFdP0-PGDQ2N7KmQA-1; Fri, 17 Jul 2026 07:54:08 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id A13BF180076C for ; Fri, 17 Jul 2026 11:54:07 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id BA9A3180034C for ; Fri, 17 Jul 2026 11:54:06 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289250; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=G2DjTqkkGv9hx92D0WNYid3pXflD4YCT9E+5cXBSj1I=; b=imq+znKrdECkWocU3NHNDkLZ4SNWk1cDzJ5qj5xCGfOkB067VdU4AN7MqAydyd4JTiyVRp Paj1vEyPPvcftTxWNKq8bKD041blpaqoudIgxUAm04HzpyCTqRLFUWJzQEYX018P0jHWRc 1dle+OyGDO5K/3MHB8t9C5uVi/EW4vc= X-MC-Unique: Hr_KGsFdP0-PGDQ2N7KmQA-1 X-Mimecast-MFC-AGG-ID: Hr_KGsFdP0-PGDQ2N7KmQA_1784289247 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:51 +0400 Subject: [GIT PULL 12/15] hw/display/virtio-gpu: cap submit_3d command buffer allocation MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-12-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=5772; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=VQljr2kxfrhnVUh+A6NaCNU6GmJHaoU7bUMaNpXzZwI=; b=owEBbAKT/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheag3kcE1OyfX3Ug/VwkWaZ8RY8P/GmR8nS6 QJWnE9Pv8qJAjIEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5YwTD/jIPrT/3ik94/GS8TFZE5O9uj0w/YdQ6wsvKlnKcpfP6jUnZBf1f3iIrWSzLMyvRGQU04I CybmjbMj1b8t1grVhFBU/G5LiH4ndBp53dZsvjODNWjkII2aAYGj+GSyYVECt4RATNUtj0MlQk3 HhVU0jVNMgdFR2hQgAVDpLe1GRk40WFjYRe/cKZUK/pw/n1A0NZu/ga4KqBqrXJ3+2kyYOO8w3c P5f59KOc1zwqXd2fgKG8c+sQkzvGq6FRVLpmklruX3Nw6pGXI+dpjyccPZzuPJerMcE6blwWbBN tN4XaPTnu+/GnRaiLyxcWbEwcql8jNXRD7cuF0a4yYiuwrZ2UVbCPWXsUqB+eaHCD9fGPgt+/EZ KSzG45m2UWsrN/VLUGWO1RCUikggdfu9itLV30zyMFCqQeOlKMgzMpUa/xKW2jdaeGv6tg7JWVR quxRlB4LL0WMfwuGmmHIGfaGQE9aTAmNTCMyMjxg5q5nOOmPCgMLNrGt+r6jD5L5zjEPS4WWRFw mBpT0VaOI0ct0B9c3euceKn0yD/i0wkLxzUzBZiVMRcRYLhl42Jucn7I/GJ5b6rEYPCwnFI+5bg mbI4YAg2RoRE6g9vB9jaRnPaWlrSgwuJmpbLatOj5hqVa85qgM+xK3M6sr1WGXzPzXlCiOrJtCA P4AjAROv6mIA4 X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289302921158500 Both virgl_cmd_submit_3d() and rutabaga_cmd_submit_3d() pass the guest-controlled cs.size directly to malloc() without bounds checking. A malicious guest can set cs.size to an arbitrarily large value, causing an OOM abort that crashes the QEMU process. Checking cs.size against the descriptor payload length (iov_size) is not sufficient: indirect descriptor tables can repeat entries aliasing the same guest-physical range, inflating iov_size() to nearly 4 GiB while referring to only a small amount of unique memory. Instead, cap cs.size at 4 MiB. With 4 KiB pages and QEMU's VIRTQUEUE_MAX_SIZE (1024) mapped-iov limit, the Linux virtio driver cannot carry more than ~4 MiB of inline command data, so legitimate submissions are unaffected. Fixes: 9d9e152136bd ("virtio-gpu: add 3d mode and virgl rendering support.") Fixes: 1dcc6adbc168 ("gfxstream + rutabaga: add initial support for gfxstre= am") Fixes: d52c454aadc ("contrib: add vhost-user-gpu") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3776 Reported-by: admin@fluentlogic.org Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau --- contrib/vhost-user-gpu/vugpu.h | 9 +++++++++ include/hw/virtio/virtio-gpu.h | 9 +++++++++ contrib/vhost-user-gpu/virgl.c | 7 +++++++ hw/display/virtio-gpu-rutabaga.c | 8 ++++++++ hw/display/virtio-gpu-virgl.c | 8 ++++++++ 5 files changed, 41 insertions(+) diff --git a/contrib/vhost-user-gpu/vugpu.h b/contrib/vhost-user-gpu/vugpu.h index 654c392fbbf..2374eb90cb9 100644 --- a/contrib/vhost-user-gpu/vugpu.h +++ b/contrib/vhost-user-gpu/vugpu.h @@ -22,6 +22,7 @@ #include "qemu/queue.h" #include "qemu/iov.h" #include "qemu/bswap.h" +#include "qemu/units.h" #include "vugbm.h" =20 typedef enum VhostUserGpuRequest { @@ -163,6 +164,14 @@ struct virtio_gpu_ctrl_command { QTAILQ_ENTRY(virtio_gpu_ctrl_command) next; }; =20 +/* + * With 4 KiB pages and QEMU's VIRTQUEUE_MAX_SIZE (1024) mapped-iov + * limit, the largest inline command is ~4 MiB. Cap submit_3d + * allocations to this value to prevent a malicious guest from + * triggering an OOM abort via an inflated cs.size field. + */ +#define VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE (4 * MiB) + #define VUGPU_FILL_CMD(out) do { \ size_t vugpufillcmd_s_ =3D \ iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, 0, \ diff --git a/include/hw/virtio/virtio-gpu.h b/include/hw/virtio/virtio-gpu.h index f69fc194627..b9bad27c97a 100644 --- a/include/hw/virtio/virtio-gpu.h +++ b/include/hw/virtio/virtio-gpu.h @@ -15,6 +15,7 @@ #define HW_VIRTIO_GPU_H =20 #include "qemu/queue.h" +#include "qemu/units.h" #include "ui/qemu-pixman.h" #include "ui/console.h" #include "hw/virtio/virtio.h" @@ -299,6 +300,14 @@ struct VirtIOGPURutabaga { struct rutabaga *rutabaga; }; =20 +/* + * With 4 KiB pages and QEMU's VIRTQUEUE_MAX_SIZE (1024) mapped-iov + * limit, the largest inline command is ~4 MiB. Cap submit_3d + * allocations to this value to prevent a malicious guest from + * triggering an OOM abort via an inflated cs.size field. + */ +#define VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE (4 * MiB) + #define VIRTIO_GPU_FILL_CMD(out) do { \ size_t virtiogpufillcmd_s_ =3D \ iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, 0, \ diff --git a/contrib/vhost-user-gpu/virgl.c b/contrib/vhost-user-gpu/virgl.c index 51da0e3667f..550fd03bf5c 100644 --- a/contrib/vhost-user-gpu/virgl.c +++ b/contrib/vhost-user-gpu/virgl.c @@ -202,6 +202,13 @@ virgl_cmd_submit_3d(VuGpu *g, =20 VUGPU_FILL_CMD(cs); =20 + if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { + g_critical("%s: command buffer too large (%u)", + __func__, cs.size); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return; + } + buf =3D g_malloc(cs.size); s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(cs), buf, cs.size); diff --git a/hw/display/virtio-gpu-rutabaga.c b/hw/display/virtio-gpu-rutab= aga.c index 6ff12639012..4d7d7b24592 100644 --- a/hw/display/virtio-gpu-rutabaga.c +++ b/hw/display/virtio-gpu-rutabaga.c @@ -351,6 +351,14 @@ rutabaga_cmd_submit_3d(VirtIOGPU *g, VIRTIO_GPU_FILL_CMD(cs); trace_virtio_gpu_cmd_ctx_submit(cs.hdr.ctx_id, cs.size); =20 + if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: command buffer too large (%u)\n", + __func__, cs.size); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return; + } + buf =3D g_new0(uint8_t, cs.size); s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(cs), buf, cs.size); diff --git a/hw/display/virtio-gpu-virgl.c b/hw/display/virtio-gpu-virgl.c index 60c78af06a4..d9e5b011049 100644 --- a/hw/display/virtio-gpu-virgl.c +++ b/hw/display/virtio-gpu-virgl.c @@ -607,6 +607,14 @@ static void virgl_cmd_submit_3d(VirtIOGPU *g, VIRTIO_GPU_FILL_CMD(cs); trace_virtio_gpu_cmd_ctx_submit(cs.hdr.ctx_id, cs.size); =20 + if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: command buffer too large (%u)\n", + __func__, cs.size); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return; + } + buf =3D g_malloc(cs.size); s =3D iov_to_buf(cmd->elem.out_sg, cmd->elem.out_num, sizeof(cs), buf, cs.size); --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289264; cv=none; d=zohomail.com; s=zohoarc; b=jqXWedkzQijVlmUEnZf8yCoHlZSgKxV93BSW34srtBqnQ+HOMNsDIv0No+bu/RK79DrVSWz6kXWeeMj1+hGLf0YY3RxC+UCfZwME4aoe+EfSMTWBhL+ZBxbvmXXQcZEbOupNEBBJmI2nSChqfGCEOpmjJb+dXL1395bQH4chp7c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289264; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Ma06sRa+gkxOkPrGVzY/3snPWHWCY9B46BWzFm1ys7k=; b=ABC62UrO8WPbvNVlDz146Gg3KQrpi5E/1C4hr+K2KROAygma2BeFQCErS801T+qcTDwNZQC5o+KXR6izt0oNCk9zahDr15CtivK/zNA0dUumSYwTAgCQ8nyTsLrLIFuJXK3DMq5Gm0z2Gpo1MsVMhMrLeusdCdbvNYXupzFV18A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289264505848.214751291472; Fri, 17 Jul 2026 04:54:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh91-0005pP-Ss; Fri, 17 Jul 2026 07:54:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8z-0005gX-QB for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:17 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh8y-0003TR-6v for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:17 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-654-l7F6mIhvPe-nof05yyTrKA-1; Fri, 17 Jul 2026 07:54:13 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AC8B91800990 for ; Fri, 17 Jul 2026 11:54:12 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C54FB1955D89 for ; Fri, 17 Jul 2026 11:54:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289255; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ma06sRa+gkxOkPrGVzY/3snPWHWCY9B46BWzFm1ys7k=; b=LI3EukKLIrRhJ7vRo/xDpdFDypAGevM5b7/31mHH5dy6+EwuX+IfU6r3V4Ma0aEuKo+KOS GpuboNEPZwVU+CboEGDFZbJvkuP39JGtTiSvtgOeLMlCP5z3YtKoJHr13qcXAJiuMHE6xN QRlwAqGjuqmVOzM7UJALG1jwEE7iFx4= X-MC-Unique: l7F6mIhvPe-nof05yyTrKA-1 X-Mimecast-MFC-AGG-ID: l7F6mIhvPe-nof05yyTrKA_1784289252 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:52 +0400 Subject: [GIT PULL 13/15] hw/display/virtio-gpu: handle migration iov allocation failure MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-13-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2315; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=2Mx0BATBe6G622ffalvUopaB0e2yv5GZQfltNK2nJQ0=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheaOORBXfwx/HO8nxwN6j1LrDuMpCnzAdm// iitwut94D+JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5RSzD/0ZmSn/UK2oZI22w2obQ+QxewcRBR/Wj+sV2n40SgNseFfDRhkRaXGvG+zrqVZHKjWKUnK Alb1UM72+Uo7UKBxM5IPFIIFSWsnxvy9ySXAY6I9svQ/qIWwQP1+3CDjl2Q2dN4ZhA5hJtWJSem D/ksbf9giF1nS8n6QlPBtosfCZwqAz5AKYZM3jvLTyaNWT8Q3tSY7vSE7UVTP5qZZZ46++fgFKf TFIY3AcnpiXOxRuA9T8SL3RGmCDmqV8AVNgnPmZeFV34PQ5Dbd20EbFE/UMTaPweZYG6s+mPS8h 7cjWf9CTL6O4D8dKb3BXPM9MUulkVe9/i5cYD7K/Fv+lPIYpbV0ObJV+VMYWe8/X5+tHfBvcTOM pgvYyOOrcSFpGV9QwwQUWHxCYcwSZxKomweX/QWTI/jV2/KX7PoEc2dV4duGmMYwkFJ4j9dbXzB q9lwvztSXVcBWGewlG+6dXDcpDIiZzNGjMthy2ftFV6pko+LbZD6d+ge9h7JNJpvSOapVuXh4mq hkw3Rx8/rdCGa0Q3FEks3vrIrYCnopNWTnqUpU+DN0tcwumEjcJWuGhvOmZUSJ/dyl73Wbi5Qus A8eHDKlFCZlB+UfsmrVhMhQ6Hsj85FudJgJA6VU/8y+Bq7wTxlRHngGAkJFi6yzqB/+GGnHmodS yW3JjY/KRrhDKXA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289264682158500 An unbounded iov_cnt from the migration stream drives two g_new() allocations whose combined size can exceed available memory, causing GLib to abort the process. Switch to g_try_new() and propagate the failure as a migration error. Fixes: 0c244e50ee12 ("virtio-gpu: add live migration support") Fixes: f66767f75c9c ("virtio-gpu: add virtio-gpu/blob vmstate subsection") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3753 Reported-by: Feifan Qian Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau --- hw/display/virtio-gpu.c | 22 ++++++++++++++++++---- 1 file changed, 18 insertions(+), 4 deletions(-) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index e00fb6effa5..048b151872e 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -1365,8 +1365,15 @@ static int virtio_gpu_load(QEMUFile *f, void *opaque= , size_t size, return -EINVAL; } =20 - res->addrs =3D g_new(uint64_t, res->iov_cnt); - res->iov =3D g_new(struct iovec, res->iov_cnt); + res->addrs =3D g_try_new(uint64_t, res->iov_cnt); + res->iov =3D g_try_new(struct iovec, res->iov_cnt); + if (res->iov_cnt && (!res->addrs || !res->iov)) { + pixman_image_unref(res->image); + g_free(res->addrs); + g_free(res->iov); + g_free(res); + return -EINVAL; + } =20 /* read data */ for (i =3D 0; i < res->iov_cnt; i++) { @@ -1440,8 +1447,15 @@ static int virtio_gpu_blob_load(QEMUFile *f, void *o= paque, size_t size, res->resource_id =3D resource_id; res->blob_size =3D qemu_get_be32(f); res->iov_cnt =3D qemu_get_be32(f); - res->addrs =3D g_new(uint64_t, res->iov_cnt); - res->iov =3D g_new(struct iovec, res->iov_cnt); + + res->addrs =3D g_try_new(uint64_t, res->iov_cnt); + res->iov =3D g_try_new(struct iovec, res->iov_cnt); + if (res->iov_cnt && (!res->addrs || !res->iov)) { + g_free(res->addrs); + g_free(res->iov); + g_free(res); + return -EINVAL; + } =20 /* read data */ for (i =3D 0; i < res->iov_cnt; i++) { --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289304; cv=none; d=zohomail.com; s=zohoarc; b=me7Tf73px7ha19zFVPG/phF8HfbYqs/WZ2JeJGheEae4Tm3QIsznt5Y++SX4PUCb086mjLxQFFJawoTWx5xm+eE4EtCylbyI45520Gob+jrX+bb8v+tWAwu2s4PcCGHLqYt2qPMjvgz6O+K2TC+0LfqYGAt/5L3BCtlR/C/fYLU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289304; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=TVeXjKZ9PQU3WPt/ZnTqRyme+JzWbiNAr/8eTl2v9XU=; b=NU0IQoApWyydF5ARs6FLaL8eG9GBlHQhNmIKgfQc2qJBCYU30ordqFobQ0aYFvNz1ibnjiFRHcMIG3IdfxRDNBq2Xd2FGynx1K7+kLdpcYykXIhw7AXvTu7DqbiiRsHQVE52exUY9mOZgS4x75TIxhFgLVOIP3xkQp5uRT9pBE8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289304207288.24625796514556; Fri, 17 Jul 2026 04:55:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh95-0005uT-6l; Fri, 17 Jul 2026 07:54:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh93-0005tr-OK for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:21 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh92-0003Th-7g for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:21 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-674-N53sqC5nPDqd3QUfKiCmrg-1; Fri, 17 Jul 2026 07:54:18 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6CC9C1954237 for ; Fri, 17 Jul 2026 11:54:17 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 863733004180 for ; Fri, 17 Jul 2026 11:54:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289259; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=TVeXjKZ9PQU3WPt/ZnTqRyme+JzWbiNAr/8eTl2v9XU=; b=dzDd56sRW0vs33ineGHE2fiKNtYXT9UlBYZi7pt2HfykFJnIIWdEhmLcycp9FiEdvlNfKT DR/iA8nM/wOnWdQ7tdpY05H2Qiem8cp3Xb0JuHvk1KfPWr6UWwyfal+t0+ZDc+PjIC9OIs FT7YsvFR5BMHfUyiguekpcBn35nyouY= X-MC-Unique: N53sqC5nPDqd3QUfKiCmrg-1 X-Mimecast-MFC-AGG-ID: N53sqC5nPDqd3QUfKiCmrg_1784289257 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:53 +0400 Subject: [GIT PULL 14/15] hw/display/virtio-gpu: reject strides exceeding INT_MAX MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-14-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=2162; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=GmgZk+S+DfdSu7csUhCv2ZCT0ku4rxhnerEsjmN1ofk=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheaKYEX3Sk9m+qUnvkeaW48K9l3fyT8Og+3y 06OO+nyNcWJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5RYVD/4rL6H4NxliTOKO/ddUvAM2Gq29pxIH5uElXq4sgc9vlbGsQx4V6V+yyMF6AxONmtfgoqw VW9zmDHSWhG1fEnpwYROQAFLxg2cOdlRxfaXLq6UpDwM+vQKKKFvX+lkswEclfiL0+ym/cTiVky pMblrQhN53P6Lp5LZrWkV0cBQsfeD+hHHGPAI1H/nwLuB9m8Fuv5yV6pphgzxdFby5sQ0YaHtjq VNocUW9qTR9yyY5vNXuTjg1XWWn9YMpc4bwHc1bLAom/l9HaTZ3Qs7KbWCMZiYGSNEADwJd3SwT A3aDojro9XoghknxSu2fYnTGmGbH3Z/Bx2TA6evM2qC2HFm5cjm8OCB41MVc66UShp6adTYIC8w r4NIlVB3D1158lfwgiVlmim/bkZoLEoUY3mwZzRv/vFAbZyyY8N1a0wuJB7oSl2jiol8ZlgLW14 yVziDut/ZlmXVljkycPIQkAlIfK3+UP2bhElOvbv7iOXQnjp8XqlAFtm9pxSvvJp9rYJxvdpkU9 pFmyrTFTicSF4XXf0JA9V0Qa9IGQJr0Zl4cLAqA+wLnp1r+pvHX7Z4tMeVmeBkveFcWVwPEiuoo 1En0wvdi/VVfE2VrW5mWmRQiAtxbd9gzmszNON41dUYmaLYpM75rFrzaysCUTBw89GQRXhmb1C/ iQzs8I/gR1pDeyQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289304888158500 From: Akihiko Odaki VIRTIO_GPU_CMD_SET_SCANOUT_BLOB supplies a guest-controlled uint32_t stride, but some downstream consumers take it as int. They may interpret a value greater than INT_MAX as negative and cause issues: - pixman_image_create_bits() takes the stride as int, and Pixman may later access memory before the blob buffer. - eglCreateImageKHR() also takes the stride as EGLint when importing the DMA-BUF, and Mesa rejects it. Reject such strides before scanout. The check in virtio_gpu_scanout_blob_to_fb() rejects unsupported blob configurations early. The check added in virtio_gpu_do_set_scanout() covers migration post_load. Fixes: 32db3c63ae11 ("virtio-gpu: Add virtio_gpu_set_scanout_blob") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260717-int-v1-1-8aa05e1791a0@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 048b151872e..3090edf89a8 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -654,6 +654,14 @@ static bool virtio_gpu_do_set_scanout(VirtIOGPU *g, return false; } =20 + if (fb->stride > INT_MAX) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: stride is %" PRIu32 + ", larger than the supported maximum (%d)\n", + __func__, fb->stride, INT_MAX); + *error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return false; + } + g->parent_obj.enable =3D 1; =20 if (res->blob) { @@ -769,6 +777,13 @@ bool virtio_gpu_scanout_blob_to_fb(struct virtio_gpu_f= ramebuffer *fb, return false; } =20 + if (fb->stride > INT_MAX) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: stride is %" PRIu32 + ", larger than the supported maximum (%d)\n", + __func__, fb->stride, INT_MAX); + return false; + } + fb->offset =3D ss->offsets[0] + ss->r.x * fb->bytes_pp + ss->r.y * fb-= >stride; =20 fbend =3D fb->offset; --=20 2.55.0 From nobody Sat Jul 25 14:07:37 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784289278; cv=none; d=zohomail.com; s=zohoarc; b=hOQeHIbx0VsFeWwW9cN0EsAEJQvM7I9xPkERQ1iedd/oscIx4PO7IyaDyNPaWBLQ/qX2msg2mAyWHrAXS0QTaGj3nU565lNhHLgGsdsH8oA549qOWNaNjPsGLbq46puKaCeHb1iFaaQteP+RCaTvvmFk5aJFlmvfk7xVphHXSb8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784289278; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=tAo6F/fuioQQPfDOiSnNumwlbG2FzGHqSpPCDaSqmRM=; b=Qmi/rIbicfdZYWKWAaTUFmvr8KkvXXHeh0lo3jyheXvycZhLv1kHHIVNlD8LRSAgmOsmCahdg/d4kUE04OU4bU4++iendsKeM1eaXbQTe1cOxpEoDFpbJ9YwNnYPIksFoi4zc92ZVw9SDV0ywkg4+COsdEhdITB3JvANm4UKJZQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784289278745980.5172587590368; Fri, 17 Jul 2026 04:54:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wkh9B-0006BB-12; Fri, 17 Jul 2026 07:54:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh99-00066B-Uy for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:27 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wkh98-0003Tx-K5 for qemu-devel@nongnu.org; Fri, 17 Jul 2026 07:54:27 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-85-aT3Qfgv9OKGx6lE6QKZDzg-1; Fri, 17 Jul 2026 07:54:24 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 5D5841955EA8 for ; Fri, 17 Jul 2026 11:54:23 +0000 (UTC) Received: from localhost (unknown [10.44.22.17]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 44E2A30040BF for ; Fri, 17 Jul 2026 11:54:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784289265; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tAo6F/fuioQQPfDOiSnNumwlbG2FzGHqSpPCDaSqmRM=; b=T0GTAlthUQLBB9oRKJJ1ENZB3QEN6wI3KKtza0hk86+UhLRAYFnmgAicDlPYnmmyO0+LDg QKRYPo10QkDLWoam6NZrqPLrH7U0lxTz6/mmHT00suu31GZ9l4uLOvnJ+sgSCpCoP0A6X+ zaUUNt//zDnpoZ+kDi69RtgQzxNvIHk= X-MC-Unique: aT3Qfgv9OKGx6lE6QKZDzg-1 X-Mimecast-MFC-AGG-ID: aT3Qfgv9OKGx6lE6QKZDzg_1784289263 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Fri, 17 Jul 2026 15:52:54 +0400 Subject: [GIT PULL 15/15] hw/display/virtio-gpu: Check pixman_image_create_bits() results MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260717-fix-v1-15-cb9f7d49dc52@redhat.com> References: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> In-Reply-To: <20260717-fix-v1-0-cb9f7d49dc52@redhat.com> To: qemu-devel@nongnu.org X-Developer-Signature: v=1; a=openpgp-sha256; l=1179; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=enz7Zo2FBPkgzgFl5nDi/U/MFOUp3ORjwYijtlJHEe8=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqWheaHN9zxTFKDiLpHvXoa/J60wNcYlO2SJOTE mUFoubCHOKJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCaloXmgAKCRDa6OEJdZac 5euID/9cgM2R5/mgNYYvQit6uL1xiLpiwUe2pOs3CwLP2afkuRTTbPyHgamcoeij7NH+io77bE/ KNV1NQt7h3vc7/Dv9auQOXBz7OkHjsDbUwfjUFcCcNKJwzldemqhLq7CvztoEiXVCUB+bQA44/N kGK8vwcs2SPLhGfjtRDYSMYPXk9ZWUXgppIQhwu8vrxOU/fyqmKyRaCnVOL1GnSghmtFdl76vam mZS9ktRNsgSD2h3NLgspJn9Qowm6FI8Gevw5OTFxRTniEvvpjbEcvkVlu/tsDycIqekzRcCcm8w 7mSgHxmGsVHibtw2cCqIfsmuw/5wVhuZjt8dDzRY/lkvtL9Qje+IfA5JSGEfgGzamR8DJdbGcuW LEhlg8ndF/WSeXte27soPmJBaPlKOlPzbpB0ltkKDLAu35pxZ7XmVcB9cMgJ0Fd11Bwb9CqIy9g QHK+Qklr2qOjYj02UHU551Qm8BwFk9jv5iO4GlmHv/oaVIaa5W50Q4mvjo5NUPNKBaRwBmSmtcu Grrw0LvmOTRsqb97+natspBzW2YT4NhdlMwPnKxqsUuuCqcRl7RqjHgGS1OiHPiZnku9hhW08Io 2Z4M6LElpmX4buIzEh9CFcF4Dzdr1KZn6U1fT+PygxxdDAqT97HIexVT0DedW+87vmivNHIp+SQ cKDCrt0g+slRQXQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784289280886158500 From: Akihiko Odaki pixman_image_create_bits() returns NULL for allocation failures and unaligned strides, which may be supplied by the guest with VIRTIO_GPU_CMD_SET_SCANOUT_BLOB, and virtio_gpu_do_set_scanout() subsequently dereferences it. Fixes: fa06e5cb7b10 ("virtio-gpu: fix scanout rectangles") Signed-off-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260717-pixman-v1-1-89ea33b50b75@rsg.ci.i.u-tokyo.ac.jp> --- hw/display/virtio-gpu.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 3090edf89a8..718ba303929 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -690,6 +690,10 @@ static bool virtio_gpu_do_set_scanout(VirtIOGPU *g, void *ptr =3D data + fb->offset; rect =3D pixman_image_create_bits(fb->format, r->width, r->height, ptr, fb->stride); + if (!rect) { + *error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; + return false; + } =20 if (res->image) { pixman_image_ref(res->image); --=20 2.55.0