From nobody Sat Jul 25 06:35:14 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784865499; cv=none; d=zohomail.com; s=zohoarc; b=Z7lEjbAJ9czrCVQYjB/H+Kqe0elgSvyT8f/R8XNfmHDjwG2HiI6zrKSeLM7zfoofzixFuyXemyonz8PQO7cs04zlpz9Atfs8+WKREkpTES4ezYyp4NDyxUmRYoj+fWuPYlY4PdiwEzAi3eX6hJDR5agTfDelS5nzuQk/FONZVWM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784865499; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=naIx8vuJNZwvieRfVQ5Og0LBIoNq1IaWbSfegzpuSmA=; b=JfeEAu13tP+nwUBkDrbbq20+EVQPtVxC9konW8wj5CdJDWJ0IERlADQE+GDoXRbctxlPHyIVKJYxxvPhc5cFNuZGESP2e9AiwEdY7OOwPYpzUwb+jLW+XbU+px6zJGkcogmvlUoLWT64DRNiwj4hpNKCiveZ8w4MAlaLFOjsHT4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784865499651555.9538749308234; Thu, 23 Jul 2026 20:58:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wn72T-0007Zp-9l; Thu, 23 Jul 2026 23:57:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wn72R-0007Zc-Tv for qemu-devel@nongnu.org; Thu, 23 Jul 2026 23:57:31 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wn72P-0007In-7X for qemu-devel@nongnu.org; Thu, 23 Jul 2026 23:57:31 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-573-BPllQCQdNG-iWOUJ528AMA-1; Thu, 23 Jul 2026 23:57:23 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 25ACA182F568; Fri, 24 Jul 2026 03:57:22 +0000 (UTC) Received: from localhost (unknown [10.44.22.7]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 59C3130002CE; Fri, 24 Jul 2026 03:57:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784865447; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=naIx8vuJNZwvieRfVQ5Og0LBIoNq1IaWbSfegzpuSmA=; b=GJB50hgMC69/z8OPy070FLbxCNFcVAVIckwQOkw6CyeGNpoFqm/Q/mNu3Ay1ZeWZco9BmR JSD8uGnwfXv3BnD/+WwxH3BeofucfxmUIyg6tjWMTvpgoV1YpD7ZNn0grChc79QhP78L3K b1Ugr5l/koeZ29yeai366Or/Z9syylM= X-MC-Unique: BPllQCQdNG-iWOUJ528AMA-1 X-Mimecast-MFC-AGG-ID: BPllQCQdNG-iWOUJ528AMA_1784865442 From: marcandre.lureau@redhat.com To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , "Michael S. Tsirkin" , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko Subject: [PATCH] hw/display/virtio-gpu: validate blob iov size in create_blob Date: Fri, 24 Jul 2026 07:57:12 +0400 Message-ID: <20260724035712.856636-1-marcandre.lureau@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -30 X-Spam_score: -3.1 X-Spam_bar: --- X-Spam_report: (-3.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.951, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784865501028158500 From: Marc-Andr=C3=A9 Lureau virtio_gpu_resource_create_blob() stores the guest-controlled blob_size without checking it against the total size of the iov backing entries. Since both values are independently guest-controlled, a malicious guest can set blob_size much larger than the actual iov backing. Subsequent SET_SCANOUT_BLOB checks bounds against the inflated blob_size, allowing a pixman surface to be created over the undersized buffer. Any display refresh then reads past the actual allocation, potentially crashing QEMU or leaking host memory contents depending on the backing type. Reject the resource early when the iov backing is smaller than the declared blob_size. Fixes: CVE-2026-66021 Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3945 Reported-by: "sundayjiang(=E8=92=8B=E6=B5=A9=E5=A4=A9)" Signed-off-by: Marc-Andr=C3=A9 Lureau --- hw/display/virtio-gpu.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index eac039c3c366..cc6dbd116618 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -372,6 +372,16 @@ static void virtio_gpu_resource_create_blob(VirtIOGPU = *g, return; } =20 + if (iov_size(res->iov, res->iov_cnt) < res->blob_size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: backing storage smaller than blob size\n", + __func__); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + virtio_gpu_cleanup_mapping(g, res); + g_free(res); + return; + } + virtio_gpu_init_udmabuf(res); QTAILQ_INSERT_HEAD(&g->reslist, res, next); } --=20 2.55.0