From nobody Fri Jul 24 05:23:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784818032; cv=none; d=zohomail.com; s=zohoarc; b=EsOQGdJp+FTpjDiZ2xxGgLs+rk8TNt2K0P8e9KKIKhK9VufFXQZYbw4SKx5wqsHOdTJuEm2fnh/U9sLId3P6Muob8BqXxQ5AYT7JlX+OdLUA4Q+nYEm77if5GJ5RX0gu5Us3fbqM6kwtjvtNuUYj2/hRhvou65Z8ZKeGHFND45I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784818032; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ro1C9a4VNUaYhe1YQZOb3MZWp+iKmkgZAyELuJt4D0Q=; b=XXmtyvlQRUCmiZcNGX8nQo7aZ8Se+0HvW2RuX5YO2iCFfinmxLDv2gxN0rEDwSQZj1wddRVIcM13bc6Xjj/naozGRwn/NZQOmaNVLdIB6CVJ9IiRlqE/RziXBd2lxvswWEZ1GZ0x4HqP+xWnDQzx24TMxIxXvzbhB8F9QXgVQNk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784818032517997.0108327794131; Thu, 23 Jul 2026 07:47:12 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmugO-0008Bk-3p; Thu, 23 Jul 2026 10:45:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmug1-00085f-QJ for qemu-devel@nongnu.org; Thu, 23 Jul 2026 10:45:37 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmufx-0002UL-L6 for qemu-devel@nongnu.org; Thu, 23 Jul 2026 10:45:33 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-310-hufl0Fk4PvOfZvVtUcIRMg-1; Thu, 23 Jul 2026 10:45:25 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9DDE01955DE3; Thu, 23 Jul 2026 14:45:23 +0000 (UTC) Received: from localhost (unknown [10.2.16.100]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D4AB0180029E; Thu, 23 Jul 2026 14:45:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784817928; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ro1C9a4VNUaYhe1YQZOb3MZWp+iKmkgZAyELuJt4D0Q=; b=XaB8Gvrph8aeV1sIPZua+WHJC2uUH2gZt68EPhNbhExiqAxIs38k44FTSMB6vLaz2U7gzR PLVSDwa9DmkhRtosCPg0Iyc6HzZvGyW9jdDRAFzDNc+1Dn1ouGEGUcjNSA9M4hEv/hAjVl ls4EJ8X6fFHI7N0iN/bd2zHH2ruVx4k= X-MC-Unique: hufl0Fk4PvOfZvVtUcIRMg-1 X-Mimecast-MFC-AGG-ID: hufl0Fk4PvOfZvVtUcIRMg_1784817924 From: Stefan Hajnoczi To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, Stefan Hajnoczi , Kevin Wolf , Hanna Reitz , boy juju , Tristan Madani Subject: [PATCH for-11.1 1/3] dmg: fix out-of-bounds load in search_chunk() (CVE-2026-65929) Date: Thu, 23 Jul 2026 10:45:17 -0400 Message-ID: <20260723144519.364701-2-stefanha@redhat.com> In-Reply-To: <20260723144519.364701-1-stefanha@redhat.com> References: <20260723144519.364701-1-stefanha@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=stefanha@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 3 X-Spam_score: 0.3 X-Spam_bar: / X-Spam_report: (0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.951, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784818033856158500 Content-Type: text/plain; charset="utf-8" The binary search in search_chunk() uses s->n_chunks as the (inclusive) upper bound. Chunk indices are in the right-open interval [0, s->n_chunks) so it is wrong to search all the way up to s->n_chunks rather than s->n_chunks - 1. The worst case security scenario I can see is convincing a victim to hotplug a malicious DMG file to a running guest, potentially causing QEMU to crash when loading from memory beyond the end of s->sectors[] or s->sectorscounts[]. This could be a denial of service. Fixes: CVE-2026-65929 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3844 Reported-by: boy juju Reported-by: Tristan Madani Signed-off-by: Stefan Hajnoczi --- block/dmg.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/block/dmg.c b/block/dmg.c index 33dcb3a3498..e325127d144 100644 --- a/block/dmg.c +++ b/block/dmg.c @@ -609,7 +609,10 @@ static inline int is_sector_in_chunk(BDRVDMGState *s, static inline uint32_t search_chunk(BDRVDMGState *s, uint64_t sector_num) { /* binary search */ - uint32_t chunk1 =3D 0, chunk2 =3D s->n_chunks, chunk3; + uint32_t chunk1 =3D 0, chunk2 =3D s->n_chunks - 1, chunk3; + if (s->n_chunks =3D=3D 0) { + goto err; /* should never happen */ + } while (chunk1 <=3D chunk2) { chunk3 =3D (chunk1 + chunk2) / 2; if (s->sectors[chunk3] > sector_num) { --=20 2.55.0 From nobody Fri Jul 24 05:23:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784817990; cv=none; d=zohomail.com; s=zohoarc; b=gO4ftIVVFKi21b/BaQpe44RpV+pJNf7+q8cmV9WHBQbWVc92I1bdUcWZPcV/ylqgAgWIvrJ8MiDyVpEeuelsy+i/+aMpx/pZGCOJocd1fs2LHQPbEU6zZiQAIxN8L7QeugmrG9IpsnFJhHL3kWvWyl8OxZ7xyEcEd9vaF84k0AY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784817990; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TzocXCl8tCAKz01IrjejhYq9aTZDjHm78Fmh0u4m9cM=; b=bqscTxk3ITBXN1jXQW20oXdtzrYu7c/AVNcYyI9Tqcy0rZ1xg8QtikfRO/GnoUc0MP58uyTVYsg+nFaSXN2p/ygNCi/S3BwSIdn7f4xDSTd0dRM5oDcuUywh0E2YfbvKOjXCBCFQXbEv/nzoAZAQ4fYCTZOV3iGSzfua/Wx0Hns= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784817990706231.22995010129011; Thu, 23 Jul 2026 07:46:30 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmugM-00088X-VS; Thu, 23 Jul 2026 10:45:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmug1-00085V-DU for qemu-devel@nongnu.org; Thu, 23 Jul 2026 10:45:37 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmufx-0002UN-Kn for qemu-devel@nongnu.org; Thu, 23 Jul 2026 10:45:32 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-482-2pF6xrGGOb-SC4nMM3EeXQ-1; Thu, 23 Jul 2026 10:45:26 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 957FD1805F34; Thu, 23 Jul 2026 14:45:25 +0000 (UTC) Received: from localhost (unknown [10.2.16.100]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 004843000225; Thu, 23 Jul 2026 14:45:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784817929; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=TzocXCl8tCAKz01IrjejhYq9aTZDjHm78Fmh0u4m9cM=; b=ioJXOEy38EbyBo1RUXZK/HdrTgAOs81cWOhv7u0lIjzJ66lgPGvoePSHvO3Xc/1TPdRNgn VyDVxLfN02lAkIOKw6mEpgZVY/T5DnIwb+D17S1tQsuGN1P8+OrkVHiUsYd8HHWd9y8djv I9z3tMhrCjFic4IPlEtmt46qetpL+nM= X-MC-Unique: 2pF6xrGGOb-SC4nMM3EeXQ-1 X-Mimecast-MFC-AGG-ID: 2pF6xrGGOb-SC4nMM3EeXQ_1784817925 From: Stefan Hajnoczi To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, Stefan Hajnoczi , Kevin Wolf , Hanna Reitz , Tristan Madani Subject: [PATCH for-11.1 2/3] dmg: refuse to open files with no chunks Date: Thu, 23 Jul 2026 10:45:18 -0400 Message-ID: <20260723144519.364701-3-stefanha@redhat.com> In-Reply-To: <20260723144519.364701-1-stefanha@redhat.com> References: <20260723144519.364701-1-stefanha@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=stefanha@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -29 X-Spam_score: -3.0 X-Spam_bar: --- X-Spam_report: (-3.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.951, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784817991662158501 Content-Type: text/plain; charset="utf-8" The dmg block driver expects the disk image file to contain at least one chunk. Refuse to open such files. This ensures that dmg block driver state always has non-NULL s->sectors[] and related fields. Note that the previous commit fixed the only known way to trigger a crash. This patch is just for defense - let's avoid opening the file and having NULL pointers in dmg block driver state. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4021 Reported-by: Tristan Madani Signed-off-by: Stefan Hajnoczi --- block/dmg.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/block/dmg.c b/block/dmg.c index e325127d144..6f8120e0338 100644 --- a/block/dmg.c +++ b/block/dmg.c @@ -559,6 +559,12 @@ static int dmg_open(BlockDriverState *bs, QDict *optio= ns, int flags, goto fail; } =20 + /* There must be at least one chunk */ + if (s->n_chunks =3D=3D 0) { + ret =3D -EINVAL; + goto fail; + } + /* initialize zlib engine */ s->compressed_chunk =3D qemu_try_blockalign(bs->file->bs, ds.max_compressed_size + 1); --=20 2.55.0 From nobody Fri Jul 24 05:23:55 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784818029; cv=none; d=zohomail.com; s=zohoarc; b=LI5UWk/LI53CRLmwwmTp6De+jmB9MmV7TYTT6oa5/1EsbqoZwmo65w7yS/iKbeMrhyoq0SgNaX0M2mtldbtUCvqk+Q9F1i0ejq7oLOGYhrlS7wmQR2zVKgLN4i20zNU3yu2OICT76ZOMYqVij4c17haBddBByALJ18CeFy4dQek= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784818029; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VRusjT/DzV9j1inJ3N5tqmW5x4Jsaa/Twelgf7arwTM=; b=hee3Kwp1x2jxkDjJqCfaypdQIC/0+0EXz/43KzC4HPaHbH5kS8f7CjXaHXeh4OJFE+Zctq89+renAi4+So1s2km61CUAdP3v2RZK8izGCoks7nMub4JRnb4YsxR0znvEF3r5xr/b+7pO6ERM54TKii62c1tWRzgz8dUL+9orQ1Y= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784818029985734.2717798162831; Thu, 23 Jul 2026 07:47:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmugO-0008CD-HA; Thu, 23 Jul 2026 10:45:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmug2-00085h-0w for qemu-devel@nongnu.org; Thu, 23 Jul 2026 10:45:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmufz-0002Ua-03 for qemu-devel@nongnu.org; Thu, 23 Jul 2026 10:45:33 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-626-p7sFCdO5Phq6AXCLSIx4ew-1; Thu, 23 Jul 2026 10:45:28 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C40991829E17; Thu, 23 Jul 2026 14:45:27 +0000 (UTC) Received: from localhost (unknown [10.2.16.100]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 253FC1956054; Thu, 23 Jul 2026 14:45:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784817930; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VRusjT/DzV9j1inJ3N5tqmW5x4Jsaa/Twelgf7arwTM=; b=Ti5JwCnChcQbFnnUaNtEt1acA53Yu4NimahTC0/E/PIy51Zx6MB7q8B7Se1UEbxviRAB+v yyBKg1R2EcJ4AfPMiDwd1NDgb2KjK9dqETetyR4nCaw0OZIQabFg7t/oONsLUsXRSvjeX4 PeVc/NuMwsyiVqFPJ5UVzCXn3SQbDZk= X-MC-Unique: p7sFCdO5Phq6AXCLSIx4ew-1 X-Mimecast-MFC-AGG-ID: p7sFCdO5Phq6AXCLSIx4ew_1784817927 From: Stefan Hajnoczi To: qemu-devel@nongnu.org Cc: qemu-block@nongnu.org, Stefan Hajnoczi , Kevin Wolf , Hanna Reitz , boy juju Subject: [PATCH for-11.1 3/3] dmg: reject inconsistent UDRW chunk sector count and length (CVE-2026-65928) Date: Thu, 23 Jul 2026 10:45:19 -0400 Message-ID: <20260723144519.364701-4-stefanha@redhat.com> In-Reply-To: <20260723144519.364701-1-stefanha@redhat.com> References: <20260723144519.364701-1-stefanha@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=stefanha@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -29 X-Spam_score: -3.0 X-Spam_bar: --- X-Spam_report: (-3.0 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.951, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784818032162158500 Content-Type: text/plain; charset="utf-8" The chunk metadata contains both: - Sector count: number of 512-byte sectors in the virtual disk - Length: number of bytes in the image file The UDRW chunk type indicates uncompressed data that can be accessed directly. The code is missing input validation to verify that sector count is consistent with length. If sector count is larger than length, then read requests can access beyond the end of the s->uncompressed_chunk buffer. This is an out-of-bounds heap access that could lead to a crash or an information leak. While we're at it, also zero the end of the last sector when length is unaligned. This prevents information leaks from the s->uncompressed_chunk buffer. Fixes: CVE-2026-65928 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3846 Reported-by: boy juju Signed-off-by: Stefan Hajnoczi --- block/dmg.c | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/block/dmg.c b/block/dmg.c index 6f8120e0338..5d7d3b8901f 100644 --- a/block/dmg.c +++ b/block/dmg.c @@ -312,6 +312,21 @@ static int dmg_read_mish_block(BDRVDMGState *s, DmgHea= derState *ds, goto fail; } =20 + /* + * Uncompressed chunk length must match sector count. Compressed c= hunks + * are validated during dmg_read_chunk() since the uncompressed si= ze is + * not known ahead of time. + */ + if (s->types[i] =3D=3D UDRW) { + if (s->sectorcounts[i] !=3D DIV_ROUND_UP(s->lengths[i], 512)) { + error_report("length %" PRIu64 " for chunk %" PRIu32 + " is inconsistent with sector count %" PRIu64, + s->lengths[i], i, s->sectorcounts[i]); + ret =3D -EINVAL; + goto fail; + } + } + update_max_chunk_size(s, i, &ds->max_compressed_size, &ds->max_sectors_per_chunk); offset +=3D 40; @@ -722,6 +737,16 @@ dmg_read_chunk(BlockDriverState *bs, uint64_t sector_n= um) if (ret < 0) { return -1; } + + /* + * Zero the unread part of the last sector when chunk length is + * unaligned to avoid exposing uninitialized memory. Valid ima= ge + * files may never hit this case, but cover it to be safe. + */ + if (s->lengths[chunk] & 511) { + size_t trailing_bytes =3D 512 - (s->lengths[chunk] & 511); + memset(s->uncompressed_chunk + s->lengths[chunk], 0, trail= ing_bytes); + } break; case UDZE: /* zeros */ case UDIG: /* ignore */ --=20 2.55.0