From nobody Mon Jul 27 12:16:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784978062; cv=none; d=zohomail.com; s=zohoarc; b=JtF19J5lKwoX8BpL6Zb7k+fCrMziay7SUIxePI9jwTGKsKtKwrFlI+I2toRNGakWF/0GfC2KwWd7g89HXu3kP0KTkLmWGlmyBEOfcxc3uaj4fK3pV3v/K3pXVbkORCkgSakiV9LtTGozK/6e2Qb8mgPKnl2AQxCYQ/49QLJIKpI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784978062; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tC4SCYq/BxIjLyeDKqtB+fePf27AX+iWrN8x03kRqWc=; b=FZlzvTWPd1eyzkLYTSHl0g8P9yWYk22uExdb2TqzvgfbySx4367YeCFT+G0eVoyxuTQD9weLR7QwjE26rbd4k4yAKnY1a85XOAHDL77NYHsyt2z2XHvA/c12s7aSpziC7SFP3S8fxOP8ro2YBSUPWdsTMPRkv+lOFylftctfOyo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784978062651721.3141405833735; Sat, 25 Jul 2026 04:14:22 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wnaKB-0006tk-Ob; Sat, 25 Jul 2026 07:13:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wnaKA-0006tQ-LX for qemu-devel@nongnu.org; Sat, 25 Jul 2026 07:13:46 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wnaK8-00068n-AK for qemu-devel@nongnu.org; Sat, 25 Jul 2026 07:13:46 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-68-5d6tmKCgOteUzWSksWMGUw-1; Sat, 25 Jul 2026 07:13:41 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3E94118005BB; Sat, 25 Jul 2026 11:13:39 +0000 (UTC) Received: from localhost (unknown [10.44.22.7]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8AFE2195422A; Sat, 25 Jul 2026 11:13:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784978022; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=tC4SCYq/BxIjLyeDKqtB+fePf27AX+iWrN8x03kRqWc=; b=N7z5r6JMjrvs3TKZ+oenOgZHz9tft12pYAf50YPj9V3wJ7GifDtGCxnizn2GqBpdXZViOq nN6SB2gonRQEDDJ9cHRG1HuiQkxFFuVPfPYh/3n598Didrp6jX0oxabff/7ssVmseGTnGN DJbZSmGBs9xVl2PpXmqdUOAudSfNX+k= X-MC-Unique: 5d6tmKCgOteUzWSksWMGUw-1 X-Mimecast-MFC-AGG-ID: 5d6tmKCgOteUzWSksWMGUw_1784978020 From: marcandre.lureau@redhat.com To: qemu-devel@nongnu.org Cc: akihiko.odaki@gmail.com, =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , "Michael S. Tsirkin" , =?UTF-8?q?Alex=20Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko Subject: [PATCH v2] hw/display/virtio-gpu: validate blob iov size Date: Sat, 25 Jul 2026 15:13:33 +0400 Message-ID: <20260725111333.1659833-1-marcandre.lureau@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -34 X-Spam_score: -3.5 X-Spam_bar: --- X-Spam_report: (-3.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.419, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784978064937154100 From: Marc-Andr=C3=A9 Lureau virtio_gpu_resource_create_blob() stores the guest-controlled blob_size without checking it against the total size of the iov backing entries. Since both values are independently guest-controlled, a malicious guest can set blob_size much larger than the actual iov backing. Subsequent SET_SCANOUT_BLOB checks bounds against the inflated blob_size, allowing a pixman surface to be created over the undersized buffer. Any display refresh then reads past the actual allocation, potentially crashing QEMU or leaking host memory contents depending on the backing type. Validate that the iov backing is at least as large as the declared blob_size in create_blob (when nr_entries > 0, since the spec permits deferred backing), attach_backing (when attaching to a blob resource), and the blob migration load path. Fixes: CVE-2026-66021 Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3945 Reported-by: "sundayjiang(=E8=92=8B=E6=B5=A9=E5=A4=A9)" Signed-off-by: Marc-Andr=C3=A9 Lureau --- v2: - moved validation to attach_backing() - added validation during blob_load() - accept nr_entries =3D=3D 0 during create_blob() --- hw/display/virtio-gpu.c | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index eac039c3c366..211a529ed720 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -372,6 +372,17 @@ static void virtio_gpu_resource_create_blob(VirtIOGPU = *g, return; } =20 + if (res->iov_cnt > 0 && + iov_size(res->iov, res->iov_cnt) < res->blob_size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: backing storage smaller than blob size\n", + __func__); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + virtio_gpu_cleanup_mapping(g, res); + g_free(res); + return; + } + virtio_gpu_init_udmabuf(res); QTAILQ_INSERT_HEAD(&g->reslist, res, next); } @@ -992,6 +1003,16 @@ virtio_gpu_resource_attach_backing(VirtIOGPU *g, cmd->error =3D VIRTIO_GPU_RESP_ERR_UNSPEC; return; } + + if (res->blob_size && + iov_size(res->iov, res->iov_cnt) < res->blob_size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: backing storage smaller than blob size\n", + __func__); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + virtio_gpu_cleanup_mapping(g, res); + return; + } } =20 static void @@ -1489,6 +1510,13 @@ static int virtio_gpu_blob_load(QEMUFile *f, void *o= paque, size_t size, res->iov[i].iov_len =3D qemu_get_be32(f); } =20 + if (iov_size(res->iov, res->iov_cnt) < res->blob_size) { + g_free(res->addrs); + g_free(res->iov); + g_free(res); + return -EINVAL; + } + if (!virtio_gpu_load_restore_mapping(g, res)) { g_free(res); return -EINVAL; --=20 2.55.0