From nobody Mon Sep 28 02:05:31 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785156791; cv=none; d=zohomail.com; s=zohoarc; b=IdXLokh9H7vUJHJv7yPmRWe1n8IUtZJWJhUSrFVEFsS2B2V2GLSfBbcvA4wkj/msguIl66Tz8JTrw2uzs3duQ80nc/KGuiQ5O5NJu+2eQPNy5fidhCmqbr8XJfCQ4DyxlXcYeSYjz/Hlh0b/ChhNyP+/w2vfoYqAwfYmEP5ODbY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785156791; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=O7SISsmVC5DR6jth9n1yAMQHhAe2WBmhf9WFDEyh/gg=; b=aXrl+S8/iBvl8WXz62MFlAqGu3DV8J2xl3pm0QTn2UTFZJIunfNFoV7SuD0EHJTs0iUSNbwuWdSyDTlQTWaQYTEY65gnELt1okvfGab+OtLVDHXjUCQobk7OTeDe9ihSfmTGBvXcjhAW3cN+n4DNoGO9lEqHk33wh4Fb4YAW/xY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785156791389286.5927346663326; Mon, 27 Jul 2026 05:53:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1woKpH-0000QE-1C; Mon, 27 Jul 2026 08:52:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKog-0008OU-95 for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:25 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKod-0004Yc-3Y for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:20 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-646-XaXgClkwOy-mJRJJxr3GXg-1; Mon, 27 Jul 2026 08:52:15 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E007E1801A32; Mon, 27 Jul 2026 12:52:13 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.178]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 58B0E1955F1F; Mon, 27 Jul 2026 12:52:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785156738; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=O7SISsmVC5DR6jth9n1yAMQHhAe2WBmhf9WFDEyh/gg=; b=dI58eBO4STwDrxsYnvZ7M4ES/AWHgdkuGJFEXIczXq5JHA+exSIF04K9L1AgBXs9iAUSK3 5wSxAjmAGxuWcNXIkcek/+dykQNygTIbgK/0MIJwHLCCKZgXK++bqXHMVVArxck93sahvY 2ufBkJpse0Gi8k7GfUVf/W2uxzzSOZE= X-MC-Unique: XaXgClkwOy-mJRJJxr3GXg-1 X-Mimecast-MFC-AGG-ID: XaXgClkwOy-mJRJJxr3GXg_1785156734 From: Thomas Huth To: qemu-devel@nongnu.org, Stefan Hajnoczi Cc: Feifan Qian , Jia Jia Subject: [PULL 1/5] hw/cxl: Validate Set Feature payload bounds Date: Mon, 27 Jul 2026 14:52:03 +0200 Message-ID: <20260727125207.646148-2-thuth@redhat.com> In-Reply-To: <20260727125207.646148-1-thuth@redhat.com> References: <20260727125207.646148-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785156792733158500 Content-Type: text/plain; charset="utf-8" From: Feifan Qian cmd_features_set_feature() derives bytes_to_copy from the mailbox input length and uses hdr->offset as the destination offset into per-feature write attribute buffers. The patrol scrub and ECS paths already reject writes where hdr->offset plus bytes_to_copy exceeds the destination structure. Add the same check to the soft PPR, hard PPR and memory sparing feature paths before copying into their write attribute buffers. Without the check, a malformed Set Feature request can write past the selected write attribute object and corrupt adjacent CXL type 3 device state. Fixes: 5e5a86bab830 ("hw/cxl: Add support for Maintenance command and Post = Package Repair (PPR)") Fixes: da5cafdc4ddd ("hw/cxl: Add emulation for memory sparing control feat= ure") Signed-off-by: Feifan Qian Reviewed-by: Thomas Huth Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3458 Reported-by: Jia Jia Signed-off-by: Thomas Huth --- hw/cxl/cxl-mailbox-utils.c | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/hw/cxl/cxl-mailbox-utils.c b/hw/cxl/cxl-mailbox-utils.c index 20e0b7e476e..ec18338b423 100644 --- a/hw/cxl/cxl-mailbox-utils.c +++ b/hw/cxl/cxl-mailbox-utils.c @@ -1813,6 +1813,10 @@ static CXLRetCode cmd_features_set_feature(const str= uct cxl_cmd *cmd, return CXL_MBOX_UNSUPPORTED; } =20 + if ((uint32_t)hdr->offset + bytes_to_copy > + sizeof(ct3d->soft_ppr_wr_attrs)) { + return CXL_MBOX_INVALID_PAYLOAD_LENGTH; + } memcpy((uint8_t *)&ct3d->soft_ppr_wr_attrs + hdr->offset, sppr_write_attrs, bytes_to_copy); set_feat_info->data_size +=3D bytes_to_copy; @@ -1832,6 +1836,10 @@ static CXLRetCode cmd_features_set_feature(const str= uct cxl_cmd *cmd, return CXL_MBOX_UNSUPPORTED; } =20 + if ((uint32_t)hdr->offset + bytes_to_copy > + sizeof(ct3d->hard_ppr_wr_attrs)) { + return CXL_MBOX_INVALID_PAYLOAD_LENGTH; + } memcpy((uint8_t *)&ct3d->hard_ppr_wr_attrs + hdr->offset, hppr_write_attrs, bytes_to_copy); set_feat_info->data_size +=3D bytes_to_copy; @@ -1851,6 +1859,10 @@ static CXLRetCode cmd_features_set_feature(const str= uct cxl_cmd *cmd, return CXL_MBOX_UNSUPPORTED; } =20 + if ((uint32_t)hdr->offset + bytes_to_copy > + sizeof(ct3d->cacheline_sparing_wr_attrs)) { + return CXL_MBOX_INVALID_PAYLOAD_LENGTH; + } memcpy((uint8_t *)&ct3d->cacheline_sparing_wr_attrs + hdr->offset, mem_sparing_write_attrs, bytes_to_copy); set_feat_info->data_size +=3D bytes_to_copy; @@ -1869,6 +1881,10 @@ static CXLRetCode cmd_features_set_feature(const str= uct cxl_cmd *cmd, return CXL_MBOX_UNSUPPORTED; } =20 + if ((uint32_t)hdr->offset + bytes_to_copy > + sizeof(ct3d->row_sparing_wr_attrs)) { + return CXL_MBOX_INVALID_PAYLOAD_LENGTH; + } memcpy((uint8_t *)&ct3d->row_sparing_wr_attrs + hdr->offset, mem_sparing_write_attrs, bytes_to_copy); set_feat_info->data_size +=3D bytes_to_copy; @@ -1887,6 +1903,10 @@ static CXLRetCode cmd_features_set_feature(const str= uct cxl_cmd *cmd, return CXL_MBOX_UNSUPPORTED; } =20 + if ((uint32_t)hdr->offset + bytes_to_copy > + sizeof(ct3d->bank_sparing_wr_attrs)) { + return CXL_MBOX_INVALID_PAYLOAD_LENGTH; + } memcpy((uint8_t *)&ct3d->bank_sparing_wr_attrs + hdr->offset, mem_sparing_write_attrs, bytes_to_copy); set_feat_info->data_size +=3D bytes_to_copy; @@ -1905,6 +1925,10 @@ static CXLRetCode cmd_features_set_feature(const str= uct cxl_cmd *cmd, return CXL_MBOX_UNSUPPORTED; } =20 + if ((uint32_t)hdr->offset + bytes_to_copy > + sizeof(ct3d->rank_sparing_wr_attrs)) { + return CXL_MBOX_INVALID_PAYLOAD_LENGTH; + } memcpy((uint8_t *)&ct3d->rank_sparing_wr_attrs + hdr->offset, mem_sparing_write_attrs, bytes_to_copy); set_feat_info->data_size +=3D bytes_to_copy; --=20 2.55.0 From nobody Mon Sep 28 02:05:31 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785156794; cv=none; d=zohomail.com; s=zohoarc; b=RxsTcw+DEeYrmTYEFlera6rTF/BzuMyHKHpCJZrfQ1nCXv4qPfeh/B7MKfSHtJ7/oLCulmWVp0GunKmVBmYZafgVAycyVop7nMoWQ7GWpk5ZhwCDv/jjTbBLjRY0ZnvsbLp95kFufekBZXjDx3YQy8/ssoIc6DpVpTMeAKXRrdw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785156794; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=n70EVbkyj4FsnRI25X971EdwRrzj2ROVm/gCaW+V0+w=; b=I77dNKgPEvZxzV7HpzaljU4RWBMn3enOYB4UQA46gvgEQIVctND719Us8+wbGflg+9S5a9lzLXr2Gh1qKSexq9hmVR5ua28jkqMt6SEeEPt807O9vjx/h8PJYtZKrrQid4QsW0DuliJYtB/E9g8bty98tYxEyMYG9E4Qkxfhm5M= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785156794742418.80894123100643; Mon, 27 Jul 2026 05:53:14 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1woKp7-00007B-2Z; Mon, 27 Jul 2026 08:52:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKok-0008Q2-3e for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKog-0004Yw-2W for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:25 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-247-hxOcB7YIPP2Kkg-DY_cTPQ-1; Mon, 27 Jul 2026 08:52:17 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 35AB91956070; Mon, 27 Jul 2026 12:52:16 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.178]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 6047A1955F7F; Mon, 27 Jul 2026 12:52:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785156741; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=n70EVbkyj4FsnRI25X971EdwRrzj2ROVm/gCaW+V0+w=; b=ZyrdS/bRmww4yzbVt5dywkVkQDwWwA4pIbtw7+fHER0VWQNFEN4jnZOAadkW7ka8Ee8Qg8 34zVZrSlgdyD1pH8rYjw6NWhFawcT6bhgww/QS4KByxz0REYT0TsGZneUgbAPe4GY16aDV BRRQVRT+gwx68jLx5cnT+oLdLX4XRQo= X-MC-Unique: hxOcB7YIPP2Kkg-DY_cTPQ-1 X-Mimecast-MFC-AGG-ID: hxOcB7YIPP2Kkg-DY_cTPQ_1785156736 From: Thomas Huth To: qemu-devel@nongnu.org, Stefan Hajnoczi Cc: Tristan Madani , Peter Maydell Subject: [PULL 2/5] hw/usb/dev-uas: Fix guest-triggerable heap OOB access Date: Mon, 27 Jul 2026 14:52:04 +0200 Message-ID: <20260727125207.646148-3-thuth@redhat.com> In-Reply-To: <20260727125207.646148-1-thuth@redhat.com> References: <20260727125207.646148-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785156796668158500 Content-Type: text/plain; charset="utf-8" From: Thomas Huth The stream ID is under control of the guest, and some spots in the code currently use it for indexing into the status3[] array without checking it for being in range first, so the code accesses the heap beyond the limit of the status3 array. Since our status delivery code depends on having a valid stream ID, we must not try to generate a fake sense code in this situation. Simply log a guest error and return early in usb_uas_command(). And to make sure that we really cannot access the status3[] array beyond its limit anymore, add some assert() statements in the affected functions, too. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3612 Reported-by: Reported-by: huntr bubble Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3986 Reported-by: Tristan Madani Suggested-by: Peter Maydell Reviewed-by: Peter Maydell Signed-off-by: Thomas Huth Message-ID: <20260720134809.573757-1-thuth@redhat.com> --- hw/usb/dev-uas.c | 29 ++++++++++++++++++++--------- 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/hw/usb/dev-uas.c b/hw/usb/dev-uas.c index 8576dfec96f..963c0433b38 100644 --- a/hw/usb/dev-uas.c +++ b/hw/usb/dev-uas.c @@ -362,6 +362,7 @@ static void usb_uas_send_status_bh(void *opaque) =20 while ((st =3D QTAILQ_FIRST(&uas->results)) !=3D NULL) { if (uas_using_streams(uas)) { + assert(st->stream <=3D UAS_MAX_STREAMS); p =3D uas->status3[st->stream]; uas->status3[st->stream] =3D NULL; } else { @@ -383,8 +384,14 @@ static void usb_uas_send_status_bh(void *opaque) =20 static void usb_uas_queue_status(UASDevice *uas, UASStatus *st, int length) { - USBPacket *p =3D uas_using_streams(uas) ? - uas->status3[st->stream] : uas->status2; + USBPacket *p; + + if (uas_using_streams(uas)) { + assert(st->stream <=3D UAS_MAX_STREAMS); + p =3D uas->status3[st->stream]; + } else { + p =3D uas->status2; + } =20 st->length +=3D length; QTAILQ_INSERT_TAIL(&uas->results, st, next); @@ -700,14 +707,22 @@ static void usb_uas_command(UASDevice *uas, uas_iu *i= u) uint16_t tag =3D be16_to_cpu(iu->hdr.tag); size_t cdb_len =3D sizeof(iu->command.cdb) + iu->command.add_cdb_lengt= h; =20 + if (uas_using_streams(uas) && tag > UAS_MAX_STREAMS) { + /* + * Our status delivery only works with valid tags, so in case the + * stream ID is out of bounds, we have to return immediately here + * without sending a fake sense_code_INVALID_TAG to the guest. + */ + qemu_log_mask(LOG_GUEST_ERROR, + "invalid tag 0x%x for USB UAS command\n", tag); + return; + } + if (iu->command.add_cdb_length > 0) { qemu_log_mask(LOG_UNIMP, "additional adb length not yet supported\= n"); goto unsupported_len; } =20 - if (uas_using_streams(uas) && tag > UAS_MAX_STREAMS) { - goto invalid_tag; - } req =3D usb_uas_find_request(uas, tag); if (req) { goto overlapped_tag; @@ -744,10 +759,6 @@ unsupported_len: usb_uas_queue_fake_sense(uas, tag, sense_code_INVALID_PARAM_VALUE); return; =20 -invalid_tag: - usb_uas_queue_fake_sense(uas, tag, sense_code_INVALID_TAG); - return; - overlapped_tag: usb_uas_queue_fake_sense(uas, tag, sense_code_OVERLAPPED_COMMANDS); return; --=20 2.55.0 From nobody Mon Sep 28 02:05:31 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785156791; cv=none; d=zohomail.com; s=zohoarc; b=KDEunw2aZaL0PC9vXTfLYMuOQ4N2n2gMaAcQyhvSNkBKtLnuC7a95d7Av1B49+v96fAGjZDd6UGgdu3YnbnVUZLXp5Zobov9L6yOVUf6G3v9nGK6Ey1IZUOJz5sZ6TSisUJDkqea4VRqYFf4Ybm68sxrTHKVPVFvg/6hsCGyGsw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785156791; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LpAuVHd/9czGszyMiEllqdNzgN2MnhueiyGjYG5vk7c=; b=QqM01UxbMofSkf0iX0JJ6jy/U6u9pMGB+TiieEFITNrt9lcvZ+5/kawxK3b4/pbfgh7z6yGGtZI2zRsoED0uhSTtXU6icZ1mLR3Hfc1oVA3KCypTQwRLCLX12yjy9JhZ7pGhHsDHCZR7DTeA/YzOB3YV7WUo3S1WIaHhMJDr4uY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785156791850650.2449161056927; Mon, 27 Jul 2026 05:53:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1woKoy-0008UZ-Fs; Mon, 27 Jul 2026 08:52:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKok-0008Q1-3e for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKof-0004Yr-Eo for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:23 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-318-iVyTovRAPvS0DPUkaso5LA-1; Mon, 27 Jul 2026 08:52:19 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 36A1B1955EA9; Mon, 27 Jul 2026 12:52:18 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.178]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C18551955F7F; Mon, 27 Jul 2026 12:52:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785156740; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=LpAuVHd/9czGszyMiEllqdNzgN2MnhueiyGjYG5vk7c=; b=Q6/oUE/mTPFliQwaLAuFr9kEtg0HJ1tSOWXxqkKYbn8VOZ331d02liDY4yMApxOwFXnbKx dMo8ZNLVtC9A2+P9mfM+tgFYaO4LErBwgazV7DRwKySGw7AaXWXipYoJkWoFz2HBkM3ZKG cxYkaJmqXH7XnsEsRzVVL5SToUc+iCc= X-MC-Unique: iVyTovRAPvS0DPUkaso5LA-1 X-Mimecast-MFC-AGG-ID: iVyTovRAPvS0DPUkaso5LA_1785156738 From: Thomas Huth To: qemu-devel@nongnu.org, Stefan Hajnoczi Cc: Alexander Bulekov Subject: [PULL 3/5] hw/ide/core: Fix possible crash via NULL pointer in ide_cancel_dma_sync() Date: Mon, 27 Jul 2026 14:52:05 +0200 Message-ID: <20260727125207.646148-4-thuth@redhat.com> In-Reply-To: <20260727125207.646148-1-thuth@redhat.com> References: <20260727125207.646148-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785156792725158500 Content-Type: text/plain; charset="utf-8" From: Thomas Huth ide_cancel_dma_sync() is called with a "IDEState *s" for one of the two IDE drives on a bus (primary or secondary drive) to cancel all pending DMA transfers on the drive. The code then checks s->bus->dma->aiocb to see whether there is any IO in flight on the *bus* and then calls blk_drain(s->blk) to wait for its completion. However, s->bus->dma->aiocb might belong to the other drive on the bus, and if there is no disk attached to the current drive, s->blk is NULL. Since blk_drain() does not check its parameter for a NULL pointer, QEMU can crash in such a case. To fix the problem, we have to check that "blk" is not NULL before calling blk_drain(). And we have to call blk_drain() for both drives, otherwise the assert(s->bus->dma->aiocb =3D=3D NULL) statement after the blk_drain() might trigger if the IO in flight belongs to the the other drive. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/905 Reported-by: Alexander Bulekov Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4052 Reported-by: dong ling Signed-off-by: Thomas Huth Message-ID: <20260721070216.82984-1-thuth@redhat.com> --- hw/ide/core.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/hw/ide/core.c b/hw/ide/core.c index 4c1ee19d8e8..fb9bf11b455 100644 --- a/hw/ide/core.c +++ b/hw/ide/core.c @@ -741,10 +741,17 @@ void ide_cancel_dma_sync(IDEState *s) * In the future we'll be able to safely cancel the I/O if the * whole DMA operation will be submitted to disk with a single * aio operation with preadv/pwritev. + * + * Note: s->bus->dma->aiocb might belong to the adjacent IDEState, + * so we have to drain both drives to get it cleared. */ if (s->bus->dma->aiocb) { trace_ide_cancel_dma_sync_remaining(); - blk_drain(s->blk); + for (int i =3D 0; i < 2; i++) { + if (s->bus->ifs[i].blk) { + blk_drain(s->bus->ifs[i].blk); + } + } assert(s->bus->dma->aiocb =3D=3D NULL); } } --=20 2.55.0 From nobody Mon Sep 28 02:05:31 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785156789; cv=none; d=zohomail.com; s=zohoarc; b=FqSs+O+pMP2dCfyXeYSttBCEM0qXMETiEHbbN/QBlRnrI68cqSeGUKxMk1dsutYPVqtb/R5Fgy0dY+ikPOJi0bPMfP5/imwdWGK/0uW441oOanbYuBZC463kpTJ+tiULODNl03ebwRlCI6vrYNeP9uVWrFnmLNf35IDp6xNgGIg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785156789; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IZdmUTHxasH+LPRv9GhPgWahT/W5LSLV13AgcmkFDs0=; b=n7N5DlicYnexHEHTd7/6UP5qqB7DfcRupHYxslhtLJto9lJur1hl6VaT2sHGytrgoIB4MLIEZOxNAAqoKL9u4iSKxcysur2tetOUDjHSEYNj84OCQcgUkdf0kgwBL/i6wKByZ4Zm4TIX52pYzVAQP/HqnPPf2d7rjLHL1yL9F0U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785156789073157.33026056356096; Mon, 27 Jul 2026 05:53:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1woKpA-0000GI-Va; Mon, 27 Jul 2026 08:52:53 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKom-0008Q5-0j for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:31 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKoj-0004ZH-TK for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:27 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-685-nGOr_njnPaS-Mfd27L7QJA-1; Mon, 27 Jul 2026 08:52:21 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 24FCE1802658; Mon, 27 Jul 2026 12:52:20 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.178]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B79981955F17; Mon, 27 Jul 2026 12:52:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785156744; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=IZdmUTHxasH+LPRv9GhPgWahT/W5LSLV13AgcmkFDs0=; b=MPjBGwy1r0PPZxdkQs+eNJxGtotH38Y+jpHG9fwmHb+2OS6Gp5QZT6IJqbwi4kOYD3x9Ah fz17PZ1WENMTNnEHOzhadnLprNHUQWT69wPDMEj3xBV1Jqy8otVp5bXy/QHB21SAH7Fa2j 1V1a3StbG3dSU/O7V2fKY9mkm+U9Oy0= X-MC-Unique: nGOr_njnPaS-Mfd27L7QJA-1 X-Mimecast-MFC-AGG-ID: nGOr_njnPaS-Mfd27L7QJA_1785156740 From: Thomas Huth To: qemu-devel@nongnu.org, Stefan Hajnoczi Cc: Yunhe Wang Subject: [PULL 4/5] hw/usb/core: Avoid possible assert() in do_parameter() --> usb_packet_copy() Date: Mon, 27 Jul 2026 14:52:06 +0200 Message-ID: <20260727125207.646148-5-thuth@redhat.com> In-Reply-To: <20260727125207.646148-1-thuth@redhat.com> References: <20260727125207.646148-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785156790464158500 Content-Type: text/plain; charset="utf-8" From: Thomas Huth usb_packet_copy() uses assert(p->actual_length + bytes <=3D iov->size) to make sure that there is enough space in the the iov. This assert() can be triggered from do_parameter() if the guest programs the XHCI in a weird way. Avoid the hard error by checking for the condition in do_parameter() first and signalling a USB_RET_STALL to the guest, just like it is done for another error condition here already some lines earlier. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3746 Reported-by: Yunhe Wang Signed-off-by: Thomas Huth Message-ID: <20260721185140.247775-1-thuth@redhat.com> --- hw/usb/core.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/usb/core.c b/hw/usb/core.c index d71204c5c80..43653c26cae 100644 --- a/hw/usb/core.c +++ b/hw/usb/core.c @@ -26,6 +26,7 @@ #include "qemu/osdep.h" #include "hw/usb/usb.h" #include "qemu/iov.h" +#include "qemu/log.h" #include "trace.h" =20 void usb_pick_speed(USBPort *port) @@ -288,6 +289,15 @@ static void do_parameter(USBDevice *s, USBPacket *p) p->status =3D USB_RET_STALL; return; } + if ((p->pid =3D=3D USB_TOKEN_OUT || p->pid =3D=3D USB_TOKEN_IN) && + setup_len > p->iov.size) { + qemu_log_mask(LOG_GUEST_ERROR, + "xhci: setup state param length %u > iov size %zu\n", + setup_len, p->iov.size); + p->status =3D USB_RET_STALL; + return; + } + s->setup_len =3D setup_len; =20 if (p->pid =3D=3D USB_TOKEN_OUT) { --=20 2.55.0 From nobody Mon Sep 28 02:05:31 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785156796; cv=none; d=zohomail.com; s=zohoarc; b=lDr5W5Cc0zd+MMqq1l1mMp2ff1Y79pbj/4kngKuzV3apQw4g7rO9FtxLEJe2Hk7f6e4PozbMeNoG9mUmYH+TFyx0Xv8r3aLyUbM+Vv/ZBim6aINLuNwuXBgigRhcSfF4JgZxLzTyuI9PTUe8E4wVZj9/OZGsN2DQ66mhsdTQXXY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785156796; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ipnCt2tZbsUnqUSL+EbqaQOVjSTVJq/44bnF1aPTAys=; b=PxcVqrw34SL1cWUqXqlzpA3zjR4CLTD7tx5jU/mOAbEVFwxV7A0eeOrY4L28gz5Niv9oqkZCSTTMUhfG+ruNqjr1IwdX6XcNeUfhH91AxH5MVvX9rMxwHfVGTlRDiBv2VYNFOR/S2iufR+uAlU122aNlgYdqYS1MUhe1fyMp9Ng= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785156796275913.45288504846; Mon, 27 Jul 2026 05:53:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1woKp7-00007P-3B; Mon, 27 Jul 2026 08:52:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKop-0008SB-Rv for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:32 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woKok-0004ZM-K1 for qemu-devel@nongnu.org; Mon, 27 Jul 2026 08:52:29 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-45-NCPJvz01OsOStR_UIhz0Sw-1; Mon, 27 Jul 2026 08:52:23 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 94E071955BD0; Mon, 27 Jul 2026 12:52:22 +0000 (UTC) Received: from thuth-p1g4.redhat.com (unknown [10.44.48.178]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C45451955F7F; Mon, 27 Jul 2026 12:52:20 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785156745; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ipnCt2tZbsUnqUSL+EbqaQOVjSTVJq/44bnF1aPTAys=; b=Nr//+vAZd8h91QBmX8xGVBhIWuP0/27RteQIDmnEg3uXUfApUFEr5HgGTLJPCNWEkXRhQS g15OlXsW6rjPQHaMR1DWqULCS8HylAliAvUm35SjshpkAP/OiCCvDnO03Tz7mG76OYdTwx PK55HSsByKOZYkjWwx2CljFe5JVZNAY= X-MC-Unique: NCPJvz01OsOStR_UIhz0Sw-1 X-Mimecast-MFC-AGG-ID: NCPJvz01OsOStR_UIhz0Sw_1785156742 From: Thomas Huth To: qemu-devel@nongnu.org, Stefan Hajnoczi Cc: Feifan Qian , Peter Maydell Subject: [PULL 5/5] hw/usb/hcd-xhci: Check return value of xhci_xfer_create_sgl() for errors Date: Mon, 27 Jul 2026 14:52:07 +0200 Message-ID: <20260727125207.646148-6-thuth@redhat.com> In-Reply-To: <20260727125207.646148-1-thuth@redhat.com> References: <20260727125207.646148-1-thuth@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=thuth@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785156796579158500 Content-Type: text/plain; charset="utf-8" From: Thomas Huth xhci_xfer_create_sgl() can fail if a guest programmed the XHCI in a weird way. The current code ignores this error, and this triggers an assert() shortly afterwards: hw/usb/core.c:612: usb_packet_copy: Assertion `p->actual_length + bytes <=3D iov->size' failed. Fix it by handling the error correctly (i.e. return with an error to the caller). While we're at it, change the DPRINTF statements in xhci_xfer_create_sgl() into proper qemu_log_mask() statements, so we have a better way to detect this situation. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3786 Reported-by: Feifan Qian Reviewed-by: Peter Maydell Signed-off-by: Thomas Huth Message-ID: <20260724110933.629791-1-thuth@redhat.com> --- hw/usb/hcd-xhci.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c index 569386b8cf1..d342aa2739e 100644 --- a/hw/usb/hcd-xhci.c +++ b/hw/usb/hcd-xhci.c @@ -1464,7 +1464,8 @@ static int xhci_xfer_create_sgl(XHCITransfer *xfer, i= nt in_xfer) switch (TRB_TYPE(*trb)) { case TR_DATA: if ((!(trb->control & TRB_TR_DIR)) !=3D (!in_xfer)) { - DPRINTF("xhci: data direction mismatch for TR_DATA\n"); + qemu_log_mask(LOG_GUEST_ERROR, + "xhci: data direction mismatch for TR_DATA\n= "); goto err; } /* fallthrough */ @@ -1474,7 +1475,8 @@ static int xhci_xfer_create_sgl(XHCITransfer *xfer, i= nt in_xfer) chunk =3D trb->status & 0x1ffff; if (trb->control & TRB_TR_IDT) { if (chunk > 8 || in_xfer) { - DPRINTF("xhci: invalid immediate data TRB\n"); + qemu_log_mask(LOG_GUEST_ERROR, + "xhci: invalid immediate data TRB\n"); goto err; } qemu_sglist_add(&xfer->sgl, trb->addr, chunk); @@ -1617,7 +1619,9 @@ static int xhci_setup_packet(XHCITransfer *xfer) } } =20 - xhci_xfer_create_sgl(xfer, dir =3D=3D USB_TOKEN_IN); /* Also sets int_= req */ + if (xhci_xfer_create_sgl(xfer, dir =3D=3D USB_TOKEN_IN) < 0) { /* Als= o sets int_req */ + return -1; + } usb_packet_setup(&xfer->packet, dir, ep, xfer->streamid, xfer->trbs[0].addr, false, xfer->int_req); if (usb_packet_map(&xfer->packet, &xfer->sgl)) { --=20 2.55.0