[PATCH] virtio-gpu: reject requests with short/truncated control headers

Ankur Saini posted 1 patch 2 months ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260728-virtio-gpu-short-header-v1-1-af19a00b100d@gmail.com
Maintainers: "Michael S. Tsirkin" <mst@redhat.com>, "Alex Bennée" <alex.bennee@linaro.org>, Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>, Dmitry Osipenko <dmitry.osipenko@collabora.com>
There is a newer version of this series
hw/display/virtio-gpu.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
[PATCH] virtio-gpu: reject requests with short/truncated control headers
Posted by Ankur Saini 2 months ago
A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
partially initialized. If the supplied bytes set the fence flag, stale
fence metadata may later be returned to the guest.

Validate the common header length before dispatch. Clear cmd_hdr and
complete malformed requests with ERR_INVALID_PARAMETER so stale fields
cannot reach the response.

Fixes: CVE-2026-18054
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
Reported-by: Ankur Saini <ankur98saini@gmail.com>
Signed-off-by: Ankur Saini <ankur98saini@gmail.com>
---
A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
partially initialized. If the supplied bytes set the fence flag, stale
fence metadata may later be returned to the guest.

Validate the common header length before dispatch. Clear cmd_hdr and
complete malformed requests with ERR_INVALID_PARAMETER so stale fields
cannot reach the response.
---
 hw/display/virtio-gpu.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
index 4d46a4eb10..15a845eff6 100644
--- a/hw/display/virtio-gpu.c
+++ b/hw/display/virtio-gpu.c
@@ -1105,8 +1105,14 @@ void virtio_gpu_process_cmdq(VirtIOGPU *g)
             break;
         }
 
-        /* process command */
-        vgc->process_cmd(g, cmd);
+        if (unlikely(iov_size(cmd->elem.out_sg, cmd->elem.out_num) <
+                     sizeof(cmd->cmd_hdr))) {
+            memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
+            virtio_gpu_ctrl_response_nodata(
+                g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
+        } else {
+            vgc->process_cmd(g, cmd);
+        }
 
         /* command suspended */
         if (!cmd->finished && !(cmd->cmd_hdr.flags & VIRTIO_GPU_FLAG_FENCE)) {

---
base-commit: 299e7557ed15a9a325620698add379a3ce2d1d95
change-id: 20260728-virtio-gpu-short-header-476aa1dae4f7

Best regards,
-- 
Ankur Saini <ankur98saini@gmail.com>
Re: [PATCH] virtio-gpu: reject requests with short/truncated control headers
Posted by Akihiko Odaki 2 months ago
On 2026/07/28 23:16, Ankur Saini wrote:
> A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> partially initialized. If the supplied bytes set the fence flag, stale
> fence metadata may later be returned to the guest.
> 
> Validate the common header length before dispatch. Clear cmd_hdr and
> complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> cannot reach the response.
> 
> Fixes: CVE-2026-18054
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
> Reported-by: Ankur Saini <ankur98saini@gmail.com>
> Signed-off-by: Ankur Saini <ankur98saini@gmail.com>

Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>

Please also fix vhost-user-gpu.

Regards,
Akihiko Odaki

> ---
> A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> partially initialized. If the supplied bytes set the fence flag, stale
> fence metadata may later be returned to the guest.
> 
> Validate the common header length before dispatch. Clear cmd_hdr and
> complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> cannot reach the response.
> ---
>   hw/display/virtio-gpu.c | 10 ++++++++--
>   1 file changed, 8 insertions(+), 2 deletions(-)
> 
> diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
> index 4d46a4eb10..15a845eff6 100644
> --- a/hw/display/virtio-gpu.c
> +++ b/hw/display/virtio-gpu.c
> @@ -1105,8 +1105,14 @@ void virtio_gpu_process_cmdq(VirtIOGPU *g)
>               break;
>           }
>   
> -        /* process command */
> -        vgc->process_cmd(g, cmd);
> +        if (unlikely(iov_size(cmd->elem.out_sg, cmd->elem.out_num) <
> +                     sizeof(cmd->cmd_hdr))) {
> +            memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
> +            virtio_gpu_ctrl_response_nodata(
> +                g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
> +        } else {
> +            vgc->process_cmd(g, cmd);
> +        }
>   
>           /* command suspended */
>           if (!cmd->finished && !(cmd->cmd_hdr.flags & VIRTIO_GPU_FLAG_FENCE)) {
> 
> ---
> base-commit: 299e7557ed15a9a325620698add379a3ce2d1d95
> change-id: 20260728-virtio-gpu-short-header-476aa1dae4f7
> 
> Best regards,
Re: [PATCH] virtio-gpu: reject requests with short/truncated control headers
Posted by Ankur Saini 2 months ago
Thanks. I found the similar path in contrib/vhost-user-gpu and will include
a minimal fix for that in v2.

On Wed, Jul 29, 2026 at 1:22 AM Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
wrote:

> On 2026/07/28 23:16, Ankur Saini wrote:
> > A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> > partially initialized. If the supplied bytes set the fence flag, stale
> > fence metadata may later be returned to the guest.
> >
> > Validate the common header length before dispatch. Clear cmd_hdr and
> > complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> > cannot reach the response.
> >
> > Fixes: CVE-2026-18054
> > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
> > Reported-by: Ankur Saini <ankur98saini@gmail.com>
> > Signed-off-by: Ankur Saini <ankur98saini@gmail.com>
>
> Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
>
> Please also fix vhost-user-gpu.
>
> Regards,
> Akihiko Odaki
>
> > ---
> > A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> > partially initialized. If the supplied bytes set the fence flag, stale
> > fence metadata may later be returned to the guest.
> >
> > Validate the common header length before dispatch. Clear cmd_hdr and
> > complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> > cannot reach the response.
> > ---
> >   hw/display/virtio-gpu.c | 10 ++++++++--
> >   1 file changed, 8 insertions(+), 2 deletions(-)
> >
> > diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
> > index 4d46a4eb10..15a845eff6 100644
> > --- a/hw/display/virtio-gpu.c
> > +++ b/hw/display/virtio-gpu.c
> > @@ -1105,8 +1105,14 @@ void virtio_gpu_process_cmdq(VirtIOGPU *g)
> >               break;
> >           }
> >
> > -        /* process command */
> > -        vgc->process_cmd(g, cmd);
> > +        if (unlikely(iov_size(cmd->elem.out_sg, cmd->elem.out_num) <
> > +                     sizeof(cmd->cmd_hdr))) {
> > +            memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
> > +            virtio_gpu_ctrl_response_nodata(
> > +                g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
> > +        } else {
> > +            vgc->process_cmd(g, cmd);
> > +        }
> >
> >           /* command suspended */
> >           if (!cmd->finished && !(cmd->cmd_hdr.flags &
> VIRTIO_GPU_FLAG_FENCE)) {
> >
> > ---
> > base-commit: 299e7557ed15a9a325620698add379a3ce2d1d95
> > change-id: 20260728-virtio-gpu-short-header-476aa1dae4f7
> >
> > Best regards,
>
>
Re: [PATCH] virtio-gpu: reject requests with short/truncated control headers
Posted by Marc-André Lureau 2 months ago
On Tue, Jul 28, 2026 at 6:47 PM Ankur Saini <ankur98saini@gmail.com> wrote:
>
> A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> partially initialized. If the supplied bytes set the fence flag, stale
> fence metadata may later be returned to the guest.
>
> Validate the common header length before dispatch. Clear cmd_hdr and
> complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> cannot reach the response.
>
> Fixes: CVE-2026-18054
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
> Reported-by: Ankur Saini <ankur98saini@gmail.com>
> Signed-off-by: Ankur Saini <ankur98saini@gmail.com>

Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>

> ---
> A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> partially initialized. If the supplied bytes set the fence flag, stale
> fence metadata may later be returned to the guest.
>
> Validate the common header length before dispatch. Clear cmd_hdr and
> complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> cannot reach the response.
> ---
>  hw/display/virtio-gpu.c | 10 ++++++++--
>  1 file changed, 8 insertions(+), 2 deletions(-)
>
> diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
> index 4d46a4eb10..15a845eff6 100644
> --- a/hw/display/virtio-gpu.c
> +++ b/hw/display/virtio-gpu.c
> @@ -1105,8 +1105,14 @@ void virtio_gpu_process_cmdq(VirtIOGPU *g)
>              break;
>          }
>
> -        /* process command */
> -        vgc->process_cmd(g, cmd);
> +        if (unlikely(iov_size(cmd->elem.out_sg, cmd->elem.out_num) <
> +                     sizeof(cmd->cmd_hdr))) {
> +            memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
> +            virtio_gpu_ctrl_response_nodata(
> +                g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
> +        } else {
> +            vgc->process_cmd(g, cmd);
> +        }
>
>          /* command suspended */
>          if (!cmd->finished && !(cmd->cmd_hdr.flags & VIRTIO_GPU_FLAG_FENCE)) {
>
> ---
> base-commit: 299e7557ed15a9a325620698add379a3ce2d1d95
> change-id: 20260728-virtio-gpu-short-header-476aa1dae4f7
>
> Best regards,
> --
> Ankur Saini <ankur98saini@gmail.com>
>
>


-- 
Marc-André Lureau