From nobody Sat Jul 25 10:11:53 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1784614252; cv=none; d=zohomail.com; s=zohoarc; b=NjLMF3FlVywlkADSA+Vt05d7Z2C5A2ueNWtxcojU5FhV1z+yFYND96zEn1HcfW/bngtqE5YXUkXnD8wMOT2NFRUM0Hp7kocASsBUmBB24JwapBWAd0Cz7+HGSlNLU9G7PoVVrR+OMZm2xv36P1CuE8WuH/zFIIccUYAYOW15uWc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784614252; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=o766GxEhV3PGRBXOiHXJb69DGsBYL5EaUQhlyW7i0BA=; b=cJDepIch0V5tb6N+yZ+xdj/iCBmfFXabjvysuIIRGyiy2GjGT/ntzTqjmbVMWmwtCY+qC3PBY7dSPEDhV/aVtFPcm8/7omTzzP4gMkyk9W5zUkl8i7bLDLpBKKEf0cDweH7++/K0OihWyqgwcUpo6UkRjTvFFgVRFalwsg+eS+8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784614252626532.963304960803; Mon, 20 Jul 2026 23:10:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wm3gQ-0004Qc-Fy; Tue, 21 Jul 2026 02:10:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wm3gJ-0004NI-Ko for qemu-devel@nongnu.org; Tue, 21 Jul 2026 02:10:21 -0400 Received: from mail-pj2-x01.google.com ([2607:f8b0:4864:39::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wm3gH-0001Me-7j for qemu-devel@nongnu.org; Tue, 21 Jul 2026 02:10:18 -0400 Received: by mail-pj2-x01.google.com with SMTP id d9443c01a7336-2ce7ac92dfcso60079795ad.1 for ; Mon, 20 Jul 2026 23:10:16 -0700 (PDT) Received: from VM-210-252-ubuntu.. ([14.116.239.40]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2cf3477eecdsm68615165ad.78.2026.07.20.23.10.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 20 Jul 2026 23:10:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784614215; x=1785219015; darn=nongnu.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=o766GxEhV3PGRBXOiHXJb69DGsBYL5EaUQhlyW7i0BA=; b=NN3BTMGMV68ijsiObLXDA2T32pmgwDBJJgEjqi0ZGAff21pRVvOokbsss6Wilu1Q+e VskPVpEtxbpmQSv903Ixs5FI3euyU1keHNV++ttCR0efQj9UMgSiniugV1BE7wGEOx9h oCV6Oo90kb/ZKDPHyb+sCiICnfh6zHZSPi3n/RAJx7z5yt/+VR0pDWrr2Dp+UssrOA7P Ii63sWU75U9s+y4GA5Y4q0ARaYYFefNa9dl7tYV+qlowUoiraQ63eMufk1u8ZQChIEaK F/8DDXS4KqDPzJAw9JLeyJ9Yq7+vPMiv3p2KrpzqgDTCqs/d+17TSAJwiSrPxurdJsL4 8mRQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784614215; x=1785219015; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=o766GxEhV3PGRBXOiHXJb69DGsBYL5EaUQhlyW7i0BA=; b=XelOLyKoMVOXF1dP6rzyg5Hwl0WGJmkP8CDY5bFBhDA/DOvUwbm9D4TUx9voAolBkx 4iC9QLsjXmZFSBIHpwwNJt+BD/C+wcBgh/qejYdviuHc3XuL9KNEzJyh3JUWfWlQiC/k OAW6SPachHnlfI1qaThS9ADlZM6zmHopif0J3uvOrPUM6gr/zhJ2GsnupIy/oe+H9Pbx QGW5e1fYb6x9OTMHSD+2fLXn+eFEaaVn6e46AjkEGwKn4he+D5lCYhwhfCrJLQPwtZtQ taZqRFUOUW/TAFxkc8dxS8CqONxBeeuxMsxbbq85gobjFb78/YMqvszSgO+LsV24SVgz bHdA== X-Gm-Message-State: AOJu0Yx6J6o1Q6xIqtjhdw7CP5xPaTBGtLssj/Gp6Oz+ZLSJEyjKWUtx NnP77iq7XmAAGlrXRmG878q8Ft9WltHUZirv1268hlUuWcnm7hY00bY35F8spFMfCSgwE37p X-Gm-Gg: AR+sD10ssFYajsoqiNmduzAq8EvxkoEvG/jBoH5yj9xglkwCk6231092DLDdu1H5bIJ gR1gSh7bu3T8A2z4/5CoInpVVxlJ/iWMp01SDtXmpd9ZdGY/1RLTq7NG7ysBmpIZb5686ZDrTH7 DvXzNsNT0d7ee51Z36uS+r1p1+zM8P8vS1R7UXBo+/xf6RDKl7adHc4rIhQA5sYnI78wpewdgOZ J0GbdA0Lr0fmgQrvPinep2QNKCndH5NO7V28FB2mvqdmJtaP5xN4qulDe9cel2vd2PipZ38rRAm LElFGVfcveZ6RShjs9Kwf/ZTqZ7Xm5ZDfKVWAleW0QBibAXi/sPhE68lHlQeN9Uw2euDeK6ow5H /6xeAvcG32RFP5Glb74toxt1kLCoVeCl6Q56uxM6JzOX+LTPCRPiMO4tw8QYaRYpkiGYKaKYM8f JZFTXWrgL23NYziJ4+5qTwKxSsUaBJEcWrQEkrrj4uEZwS7ZVpizwkZY7jP/FFxZZAt0yzMAevq Aph91QhAaeB8OmYtl3uaT0LBerfHg== X-Received: by 2002:a17:902:c411:b0:2c9:97a9:2096 with SMTP id d9443c01a7336-2cf349edab6mr171939945ad.42.1784614215156; Mon, 20 Jul 2026 23:10:15 -0700 (PDT) From: jianghaotian.sunday@gmail.com To: qemu-devel@nongnu.org Cc: kraxel@redhat.com, philmd@redhat.com, thuth@redhat.com, alxndr@bu.edu, qemu-stable@nongnu.org, Haotian Jiang Subject: [PATCH] hw/audio/intel-hda: restrict all DMA engine paths to memories Date: Tue, 21 Jul 2026 14:09:41 +0800 Message-Id: <20260721060941.2989396-1-jianghaotian.sunday@gmail.com> X-Mailer: git-send-email 2.34.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:39::1; envelope-from=jianghaotian.sunday@gmail.com; helo=mail-pj2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @gmail.com) X-ZM-MESSAGEID: 1784614254428158500 Content-Type: text/plain; charset="utf-8" From: Haotian Jiang CVE-2021-3611 (commit 79fa99831d) restricted the DMA engine to memories by setting attrs.memory=3Dtrue, but only applied this to intel_hda_response. Three other DMA engine access points still use MEMTXATTRS_UNSPECIFIED, allowing a malicious guest to trigger DMA-to-self-MMIO reentry: - intel_hda_xfer (line 398): called from the audio timer callback (hda_codec_xfer -> bus->xfer), so the MemReentrancyGuard does not fire (engaged_in_io is false outside MMIO dispatch). A guest that points a BDL entry at the HDA controller's own MMIO BAR can write audio samples to device registers, triggering whandler side effects such as starting/stopping streams or injecting codec commands via CORBWP. - intel_hda_parse_bdl (line 478): uses pci_dma_read which hardcodes MEMTXATTRS_UNSPECIFIED. A guest-controlled BDL base address can point at controller MMIO, allowing the DMA engine to read device registers as BDL descriptors. - intel_hda_corb_run (line 333): ldl_le_pci_dma reads the CORB ring with MEMTXATTRS_UNSPECIFIED, allowing the DMA engine to read controller MMIO as CORB entries. Fix all three by passing {.memory =3D true} explicitly, matching the fix already applied to intel_hda_response. For intel_hda_parse_bdl, replace pci_dma_read with pci_dma_rw to pass the controlled attrs. Fixes: 79fa99831d ("hw/audio/intel-hda: Restrict DMA engine to memories (no= t MMIO devices)") Reported-by: Haotian Jiang of Tencent Security (Yunding Lab) Signed-off-by: Haotian Jiang Cc: qemu-stable@nongnu.org Reviewed-by: Philippe Mathieu-Daud=C3=A9 --- hw/audio/intel-hda.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/hw/audio/intel-hda.c b/hw/audio/intel-hda.c index d7c2c3c2fd..3d361a4976 100644 --- a/hw/audio/intel-hda.c +++ b/hw/audio/intel-hda.c @@ -305,6 +305,7 @@ static int intel_hda_send_command(IntelHDAState *d, uin= t32_t verb) =20 static void intel_hda_corb_run(IntelHDAState *d) { + const MemTxAttrs attrs =3D { .memory =3D true }; hwaddr addr; uint32_t rp, verb; =20 @@ -330,7 +331,7 @@ static void intel_hda_corb_run(IntelHDAState *d) =20 rp =3D (d->corb_rp + 1) & 0xff; addr =3D intel_hda_addr(d->corb_lbase, d->corb_ubase); - ldl_le_pci_dma(&d->pci, addr + 4 * rp, &verb, MEMTXATTRS_UNSPECIFI= ED); + ldl_le_pci_dma(&d->pci, addr + 4 * rp, &verb, attrs); d->corb_rp =3D rp; =20 dprint(d, 2, "%s: [rp 0x%x] verb 0x%08x\n", __func__, rp, verb); @@ -395,7 +396,7 @@ static void intel_hda_response(HDACodecDevice *dev, boo= l solicited, uint32_t res static bool intel_hda_xfer(HDACodecDevice *dev, uint32_t stnr, bool output, uint8_t *buf, uint32_t len) { - const MemTxAttrs attrs =3D MEMTXATTRS_UNSPECIFIED; + const MemTxAttrs attrs =3D { .memory =3D true }; HDACodecBus *bus =3D HDA_BUS(dev->qdev.parent_bus); IntelHDAState *d =3D container_of(bus, IntelHDAState, codecs); hwaddr addr; @@ -466,6 +467,7 @@ static bool intel_hda_xfer(HDACodecDevice *dev, uint32_= t stnr, bool output, =20 static void intel_hda_parse_bdl(IntelHDAState *d, IntelHDAStream *st) { + const MemTxAttrs attrs =3D { .memory =3D true }; hwaddr addr; uint8_t buf[16]; uint32_t i; @@ -475,7 +477,8 @@ static void intel_hda_parse_bdl(IntelHDAState *d, Intel= HDAStream *st) g_free(st->bpl); st->bpl =3D g_new(bpl, st->bentries); for (i =3D 0; i < st->bentries; i++, addr +=3D 16) { - pci_dma_read(&d->pci, addr, buf, 16); + pci_dma_rw(&d->pci, addr, buf, 16, + DMA_DIRECTION_TO_DEVICE, attrs); st->bpl[i].addr =3D le64_to_cpu(*(uint64_t *)buf); st->bpl[i].len =3D le32_to_cpu(*(uint32_t *)(buf + 8)); st->bpl[i].flags =3D le32_to_cpu(*(uint32_t *)(buf + 12)); --=20 2.34.1