From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828002; cv=none; d=zohomail.com; s=zohoarc; b=L1gg6vNiCFnU1uEvUDYZitFp6HmgIwpWaJvZ3za5cxCOnVZ44JKdbjrXpwr2NFMbU1idlDBOR/M1iSghpqZcMMH18UKQReIEgMNKIt5PCM9ICoe64LcT7RSJrrmv9sIGSvou/UVI8ece5BoP2V44OHugBXeiMA4W6y+8xviZraQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828002; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=3AnR5+gsJzHOo4gwdjec5GVmM1fFGwyr/nH1Jm5SbeU=; b=MrNJaaHRdn5l555u9Yj+5dpbtr54bIha5SFNZBFpxUJhr1Qo0joaYBcUkKuF4bPdvKe2+BM2vCyl+MOqUP9HmU3r8cdh/nAICD9gF4wEuFp4l7mWPGtPfMpFYlKsZXIZg+BrwAUlC73dv65JBqSYEWqqhxGvivLflTbT2QEh7Lg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828002248788.0790245460599; Tue, 4 Aug 2026 00:20:02 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9RL-0000sq-U4; Tue, 04 Aug 2026 03:19:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9RJ-0000qV-Oa for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:19:53 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9RI-0001G2-46 for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:19:53 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-538-Ll1zFr1SMcqGk_uPHUv2eQ-1; Tue, 04 Aug 2026 03:19:46 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 98F6319560AA; Tue, 4 Aug 2026 07:19:44 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 040DE414; Tue, 4 Aug 2026 07:19:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785827990; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=3AnR5+gsJzHOo4gwdjec5GVmM1fFGwyr/nH1Jm5SbeU=; b=FIQ7FU/oVAsuD4ZnTur24TGkGvgY6CDyz2r4drplN+3JoT9tJ1t4JYA41RynnHAf0fDjaF ZDxMDmN6ZnJa7QZKWTdQE3eDlg/WNGXLxHXMF/wacA2lN7LQgm4Kmul5ntlY5IWQC32hea K8bf19OiTnzfsbh4dHWkthH+wTA65BE= X-MC-Unique: Ll1zFr1SMcqGk_uPHUv2eQ-1 X-Mimecast-MFC-AGG-ID: Ll1zFr1SMcqGk_uPHUv2eQ_1785827985 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:50 +0400 Subject: [GIT PULL 1/9] hw/display/virtio-gpu: validate blob iov size MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-1-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko , "Michael S. Tsirkin" X-Developer-Signature: v=1; a=openpgp-sha256; l=3166; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=6qeQBZsDpxxlBX+APuClWKzBBwDA/wesXR/QCuI+oMI=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJcr4E3CvzxIOj/+6K9KLTkFdn+vGML0ULhT AND/7u1TOSJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXAAKCRDa6OEJdZac 5SjKD/4ib11IR0bPyri0ox7hu39KM9FzXnU4Ac2uQOlV+AvTtDs71VFOF3DrinHU1synkwb7CYF X7CexXSAqKy6d8QWWe6EMu4j3rkMkQ4n8MBPVBuOOPxRw9fTgTEpOiH7iES2JkWaftknW7dE4PF HLgLx4G2CcRUHz8IRw/pQj6EbGt+vYALl0C/748DR7YBFR2KbCofdeIUQC0X+IEci2KL7P3bNp3 nHajmky31u7rwdQcOi5ioNZOrz3dE19SDUaA3RN8amV36CmboAQEP0ZWY2RQNPzW7yeA+vDjA77 MUOHGqadD8+kuST5iHBdsKUr6pHGrwgkFgyfagh8e+1J1sxSJUSjCZFzSPlbuXWF51AxSn0kc8y 6Q8YSERrkoWVHwiVunMEPN5lj4TOFIEKeMyMCY64dLI80Z9IMYekvy3HeqtSROGZQE9aPU/+lq7 Df4nhijQ6wPhDtsZuNiL9YcQRcdvVg4WxdDZWUi/CSPl4SEQvK2RSLxYsT/Qlnko7j0xNeSJ1On SLy5DPlERB0bmWW6aKxwMhnh0zYrgJNadcoS/nb85eR4UFHM6oI+TK//Dt3E6FGwLwwDo/ywpi/ 4duakQVeXG0VCC21mHWlxriHslcu9dh9gaIRrF5/dPlgUttj2CTOFhmZGuF93N3nws3q+12C0jd KbmDi2H47kyPn+Q== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828003003158500 virtio_gpu_resource_create_blob() stores the guest-controlled blob_size without checking it against the total size of the iov backing entries. Since both values are independently guest-controlled, a malicious guest can set blob_size much larger than the actual iov backing. Subsequent SET_SCANOUT_BLOB checks bounds against the inflated blob_size, allowing a pixman surface to be created over the undersized buffer. Any display refresh then reads past the actual allocation, potentially crashing QEMU or leaking host memory contents depending on the backing type. Validate that the iov backing is at least as large as the declared blob_size in create_blob (when nr_entries > 0, since the spec permits deferred backing), attach_backing (when attaching to a blob resource), and the blob migration load path. Fixes: CVE-2026-66021 Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3945 Reported-by: "sundayjiang(=E8=92=8B=E6=B5=A9=E5=A4=A9)" Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260729161431.1180691-1-marcandre.lureau@redhat.com> --- hw/display/virtio-gpu.c | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 4d46a4eb10fa..0206910cc377 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -372,6 +372,17 @@ static void virtio_gpu_resource_create_blob(VirtIOGPU = *g, return; } =20 + if (res->iov_cnt > 0 && + iov_size(res->iov, res->iov_cnt) < res->blob_size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: backing storage smaller than blob size\n", + __func__); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + virtio_gpu_cleanup_mapping(g, res); + g_free(res); + return; + } + virtio_gpu_init_udmabuf(res); QTAILQ_INSERT_HEAD(&g->reslist, res, next); } @@ -993,6 +1004,15 @@ virtio_gpu_resource_attach_backing(VirtIOGPU *g, return; } =20 + if (iov_size(res->iov, res->iov_cnt) < res->blob_size) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: backing storage smaller than blob size\n", + __func__); + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + virtio_gpu_cleanup_mapping(g, res); + return; + } + if (!res->image) { virtio_gpu_init_udmabuf(res); } @@ -1493,6 +1513,14 @@ static int virtio_gpu_blob_load(QEMUFile *f, void *o= paque, size_t size, res->iov[i].iov_len =3D qemu_get_be32(f); } =20 + if (res->iov_cnt > 0 && + iov_size(res->iov, res->iov_cnt) < res->blob_size) { + g_free(res->addrs); + g_free(res->iov); + g_free(res); + return -EINVAL; + } + if (!virtio_gpu_load_restore_mapping(g, res)) { g_free(res); return -EINVAL; --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828021; cv=none; d=zohomail.com; s=zohoarc; b=VlsvKQRkqS4aaHzvx7r91P75lGOpEP5oShcMWyl7whUfTLatSaK6KeoXqgoPTzffdfHLfj1xAUsqDtVINx5xoKaXilN5zEVIAVspcRyhEUp3nYm9/xMoamy8mU1NkJg9qb6+eSBsYmdCglvJnSM3ONPnevl1OO2Jz8AGsbTM9CI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828021; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bXadFxbNPeUF1U0eYN9ts7zWvNYvwxNB1dgDghPB4oc=; b=Hb1CATp9HaH63c7ouViex1AALCqG4Co/Q+HiQ1cr0XrnvGrGaVHg+shcD0BmY92UaK8sZQiRRouamCI32FDKc56vB176odM5HPTw/GrCYHBfsCe1bSibdXQJaesraJJfCgOE/O3YnuCMIqP560A9I8BEimIpQQgdqy6vyaEh1NA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828021686958.6617874896036; Tue, 4 Aug 2026 00:20:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9RP-0000tt-9k; Tue, 04 Aug 2026 03:19:59 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9RN-0000tc-RO for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:19:57 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9RM-0001GG-75 for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:19:57 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-620-lMNADT0lNmGppKpsMoZ72g-1; Tue, 04 Aug 2026 03:19:54 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 85CE3195605F for ; Tue, 4 Aug 2026 07:19:53 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 41EEF195608D; Tue, 4 Aug 2026 07:19:50 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785827995; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=bXadFxbNPeUF1U0eYN9ts7zWvNYvwxNB1dgDghPB4oc=; b=dbqqpPsMUvBwGplf8AwagioXqCuGpSqSY6NBLRLwTLuAMLs7cti4pR7sGP+fLbknnnbYxw 7eJb9Dg2Ucb+DdrRtengHb/M5m7TmA8R7l/t/rxWaevVH4IA2O54/SDg9lo9b5pm6r2WE9 4CAfCUZxTmu/DL10eOFvBWB8ifLVheU= X-MC-Unique: lMNADT0lNmGppKpsMoZ72g-1 X-Mimecast-MFC-AGG-ID: lMNADT0lNmGppKpsMoZ72g_1785827993 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:51 +0400 Subject: [GIT PULL 2/9] hw/display/vga: fix panning_buf OOB after text/graphics switch MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-2-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, Gerd Hoffmann X-Developer-Signature: v=1; a=openpgp-sha256; l=2761; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=E7/JuJnX61sx5FrqxASrVT+wu20t+91TLiJoppvHx8w=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJckFCqPJ2cTeg8dipYs2ONkfleMtTj6mJ+f isLmG5A5HSJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXAAKCRDa6OEJdZac 5egSD/0ToFOCI+d+QejzNxRLbVbg/4FnH3opORSlW804ZgSKu7+3t+VEAu8Wzf4RzX4RcqqGoSt /WTGu47lQw3KG/YLglKbmRYqqvctGYxfNnmzMZojUT3W+dQ9lEdbwEACqCfzvEfciqFNpmf9E9E O7dLalRY7VAOS9kZhFWJkev1B0GZE/GPN1R5BisDT0tEI5eiuoN5NyZH66XHs0Sfhu+7HF7oczK kaOuPmy533KBC0jmhVvgoxKcerBqA7Bnpm/rFzsF+FuC7JWHaRtssiP/tE+btiK90tBmDrtTai7 7qeXRLRbOClDnN1AkwNhMccU1mbWS90sD6ML4vb1EIWpEKWlnTNb05qnerxamesYvLnfMa7fcuW VTwPOKtnlf36YSm01W2Kgag7gcqCsKorBWUznlBQKZsZFQMe7uqsKk1cqDwvlrj0Cx1O+Pky99P aOdxhDEetnJahh5J5Y+CbHGKaEsAtqEHwClMj582iOTj0hcXR/+gqOETJkPmDqUH3HGy9azIdnH zgQZic1k6UMSCGW2lU3+wnKVfSD3glNyN6VmZ0ffbLCC68qgE9pQzZ47WMZkICwjZE7KfCqXJ4j /GLqNkcAFWcZwxQs5xTak3e7kx427znxtlAooOdQH0O+PQHg5At1jOLdOuywGY3spR6zfQJCBW/ HwTco5i31/elw4Q== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828022716158500 The fields last_width and last_height serve two purposes: the text renderer counts in characters, the graphics renderer in pixels. panning_buf reallocation is guarded by geometry-change check, so the unit mismatch can trick it into thinking nothing changed when the resolution actually grew. A guest can trigger this by switching graphics -> text -> graphics: 1. Enter graphics mode with a small width (CR01=3D0x00, 8 pixels). The predicate fires and panning_buf is allocated for that width. 2. Switch to text mode with a large width (CR01=3D0xFF, 256 chars). The text renderer stores 256 into last_width. The text path never touches panning_buf. 3. Switch back to graphics with a width that happens to equal 256 in pixels (CR01=3D0x1F, 32*8 =3D 256). The predicate sees 256 =3D=3D 256 and skips the realloc. With horizontal pel panning enabled, vga_draw_line4() then writes a full 256-pixel scanline into the buffer still sized for 8 pixels -- a 960-byte heap overflow on every scanline, every refresh. Fix it by reallocating unconditionally panning_buf on vga_draw_graphic(). Fixes: CVE-2026-17516 Fixes: 973a724eb006 ("vga: implement horizontal pel panning in graphics mod= es") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4085 Cc: Paolo Bonzini Signed-off-by: Warisjeet Singh [ Marc- Andr=C3=A9 - drop realloc() resize condition & commit message ] Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260728151456.3704099-1-marcandre.lureau@redhat.com> --- hw/display/vga.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/hw/display/vga.c b/hw/display/vga.c index abe3f8e07758..da0c331486eb 100644 --- a/hw/display/vga.c +++ b/hw/display/vga.c @@ -1647,11 +1647,12 @@ static void vga_draw_graphic(VGACommonState *s, int= full_update) s->last_line_offset =3D s->params.line_offset; s->last_depth =3D depth; s->last_byteswap =3D byteswap; - /* 16 extra pixels are needed for double-width planar modes. */ - s->panning_buf =3D g_realloc(s->panning_buf, - (disp_width + 16) * sizeof(uint32_t)); full_update =3D 1; } + + /* 16 extra pixels are needed for double-width planar modes. */ + s->panning_buf =3D g_realloc(s->panning_buf, + (disp_width + 16) * sizeof(uint32_t)); if (surface_data(surface) !=3D s->vram_ptr + (s->params.start_addr * 4) && !surface_is_allocated(surface)) { /* base address changed (page flip) -> shared display surfaces --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828033; cv=none; d=zohomail.com; s=zohoarc; b=TRBHqqKueDYAi2XI80viJ1bSQhOUuFcaMR2ki0GJX1q3zHu8ZW3EoGo5JKqAGNcUF/pqwSjTMIdWQ2iTgM2f9ikkA6sISSvSbomv/WyiUQTbNYfiPdtde61pk1MPcqdzL6uJ7lW9DDM2CMohmwKlUAr7+YFWkUhV09o+Bu+SQK0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828033; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=t13M/Czg5AHMi5OAxhOkC6Djts0zl5Cej5RLjx8EdFY=; b=NL/FQziNHwBh25jYAhlr7dWpKegW194jxS/q8kbG32XtrR/s7RAiMEJDNpJLe5u8a5dWQIhIMFU/b0IazDMW1EAEvRC4opzKbYeSuUYx8V0HkmW8Hxb2FOoK7YPRLl3N6ARoGNF3wQabVwtcVZXJtcszHBWBO2qJsJf/UTQzD88= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828033124527.3965353035363; Tue, 4 Aug 2026 00:20:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9Rs-0001Pc-TR; Tue, 04 Aug 2026 03:20:28 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Rr-0001FF-1i for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:27 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Rp-0001Tv-AI for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:26 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-59-tTevSrokPwKncktPVLUFMw-1; Tue, 04 Aug 2026 03:20:18 -0400 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9FD3C1956096 for ; Tue, 4 Aug 2026 07:20:17 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 189B3195608E; Tue, 4 Aug 2026 07:20:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828024; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=t13M/Czg5AHMi5OAxhOkC6Djts0zl5Cej5RLjx8EdFY=; b=ZQzE3tP0jXNTPozns09LnFoU6k7fqP1+m+1H0NTOQYpn5AspCnOQ0CzFmpnnDUQVvy8CG1 KlYsyYA+XopDmf/yLRV4M5uv5wdwfZsQnAOLhmfOg01Kb22r7L2KUZRJ0c8G8vBEHb02yq FVr7JA6fOhg/oisNNAB/IwlgPctwotU= X-MC-Unique: tTevSrokPwKncktPVLUFMw-1 X-Mimecast-MFC-AGG-ID: tTevSrokPwKncktPVLUFMw_1785828017 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:52 +0400 Subject: [GIT PULL 3/9] vhost-user-gpu: fix integer overflow in buffer allocation MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-3-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , "Michael S. Tsirkin" , Stefano Garzarella X-Developer-Signature: v=1; a=openpgp-sha256; l=3614; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=uJQIwrzvbpkpuaroaHRi5aMKPCT+/mMRyL4Qh11QYyg=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdLGljg4fi2alpWuoAkCr+K86gyCbys3luU Zq4mxXUcXCJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5fn+EACnXui2/m4AHPCropVSoD3dgTb3oydDi7qPnEIhumEoZ5INPKc/zdKFvcOUWXl6zsh6jlC 7T/L3GZrWoF5AyW2B4Vgk47Cty+X9f25azPd/DnD+AWGl32/ZrR2pI2FsUxY7o1Oqld7Nyi1KMV q0o05c7niRQ5NpbGCzYmiKQr537hLC5VhnzOadvvPyCc6kJk9/zHrzIdp1G4irgpTb6FKKPV9sJ 45OOOYxDtJZ5j9AmPmarmrD7v7guZ4wLgTXPen0xJzyqiVNl6+Hsd7R2OxNY2TrboJRupbCpgBn 9BRD6S26avpE9VCGa28axJxcaENAmz0gPJJahXa/O6OVRJLYHdup1AZWFLfTiSQz/nn6R6v+pJK qLXtcwjUzcOwK1ELkd5YkXwlRpvRenOikGrw9y8vGEnzRfxyZFLfOymr6C33JisSfqVXTxAS2I7 Yucnv9pvnpUt2ATrtVhaJyK0ZwWFAUw+UPD6yG+bLE7FO8GfMqwpuKr6oZ/R8u+r5d79qlrz2mx cDgH1ERNYsICRZcYbzcSbNbug2WOHxm6ter0w/9xR5Ieg36G3kVAjXYqzhlygMFexPrGYrMf00A M+t9rJMFfdlB0s7AEfqGybfRMBiVHJG2VuvGG7GLcUGd4rfJwZNZGRN0rJy5elvYWpvhQqv7cXn +64oACdg+f7kv1w== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828034833158500 A malicious guest can trigger a heap buffer overflow in the vhost-user-gpu backend by sending a VIRTIO_GPU_CMD_RESOURCE_CREATE_2D with large width and height values (e.g. 65537x65537). The allocation size width * height * 4 silently wraps in uint32_t arithmetic, resulting in a much smaller allocation than expected. Subsequent VIRTIO_GPU_CMD_TRANSFER_TO_HOST_2D writes past the heap buffer. The in-tree virtio-gpu device (hw/display/virtio-gpu.c) already handles this via calc_image_hostmem() with uint64_t arithmetic and an overflow check. Apply the same approach to the vhost-user-gpu contrib backend: - Add an overflow check in vugbm_buffer_create() rejecting dimensions where width * height * 4 exceeds UINT32_MAX - Promote the size arithmetic to uint64_t in mem_alloc_bo() and udmabuf_get_size() - Check the return value of vugbm_buffer_create() in vg_resource_create_2d(), which was previously ignored Fixes: CVE-2026-15264 Reported-by: "Vulnerability Report" Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3940 Signed-off-by: Marc-Andre Lureau Acked-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20260710134720.2317856-1-marcandre.lureau@redhat.com> --- contrib/vhost-user-gpu/vhost-user-gpu.c | 8 +++++++- contrib/vhost-user-gpu/vugbm.c | 11 +++++++++-- 2 files changed, 16 insertions(+), 3 deletions(-) diff --git a/contrib/vhost-user-gpu/vhost-user-gpu.c b/contrib/vhost-user-g= pu/vhost-user-gpu.c index bb41758e3454..ee9858c397ce 100644 --- a/contrib/vhost-user-gpu/vhost-user-gpu.c +++ b/contrib/vhost-user-gpu/vhost-user-gpu.c @@ -388,7 +388,13 @@ vg_resource_create_2d(VuGpu *g, cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; return; } - vugbm_buffer_create(&res->buffer, &g->gdev, c2d.width, c2d.height); + if (!vugbm_buffer_create(&res->buffer, &g->gdev, c2d.width, c2d.height= )) { + g_critical("%s: buffer creation failed %d %d %d", + __func__, c2d.resource_id, c2d.width, c2d.height); + g_free(res); + cmd->error =3D VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; + return; + } res->image =3D pixman_image_create_bits(pformat, c2d.width, c2d.height, diff --git a/contrib/vhost-user-gpu/vugbm.c b/contrib/vhost-user-gpu/vugbm.c index 503d0a4566f8..710d54529779 100644 --- a/contrib/vhost-user-gpu/vugbm.c +++ b/contrib/vhost-user-gpu/vugbm.c @@ -13,7 +13,7 @@ static bool mem_alloc_bo(struct vugbm_buffer *buf) { - buf->mmap =3D g_malloc(buf->width * buf->height * 4); + buf->mmap =3D g_malloc((uint64_t)buf->width * buf->height * 4); buf->stride =3D buf->width * 4; return true; } @@ -53,7 +53,8 @@ struct udmabuf_create { static size_t udmabuf_get_size(struct vugbm_buffer *buf) { - return ROUND_UP(buf->width * buf->height * 4, qemu_real_host_page_size= ()); + return ROUND_UP((uint64_t)buf->width * buf->height * 4, + qemu_real_host_page_size()); } =20 static bool @@ -293,6 +294,12 @@ bool vugbm_buffer_create(struct vugbm_buffer *buffer, struct vugbm_device *dev, uint32_t width, uint32_t height) { + uint64_t size =3D (uint64_t)width * height * 4; + if (size > UINT32_MAX) { + g_warning("buffer dimensions too large: %ux%u", width, height); + return false; + } + buffer->dev =3D dev; buffer->width =3D width; buffer->height =3D height; --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828048; cv=none; d=zohomail.com; s=zohoarc; b=gUDvUWpv8liM6ZbzbY4NAZ+kDmLf/EIMwN2wMpPhgqOk0DG6dx/DcJmi1F7zjFDxGZNcXvK+FeihqZm4VgP06282t5iQtsZi07JCg8Bnm+zFWHB5XAGqG2anDh5pMgEnIkAj9KvSM3SUTXmKJ59v+GLxqFJ1UA9PMCl6JaUZ7Uk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828048; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JBuZeH/hyIo3fbh1PQfwbL8P51yWnlk8B0Vwt9xpvUY=; b=cT6vDiUx18HPYF7CLZV9/fCUdp+J9cZA+UC45iC2b2VSXF0z1ZDntxQofGQKmhg6iBEA1k6dr+J9a6mImFK8r7HGnJkmqoQxxD1jHM6/SX9DbKEkXXSaGuPGScAbsICePON/3SHMypCQQHqFP0M1ECIjOlYMdhki6fsZmr0SuQc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828048666150.69507452575772; Tue, 4 Aug 2026 00:20:48 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9S7-0001zM-Cv; Tue, 04 Aug 2026 03:20:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Ry-0001tp-0q for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:35 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Rw-0001UK-A2 for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:33 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-611-V2GN3pU_MJuAXzrr380JHQ-1; Tue, 04 Aug 2026 03:20:28 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6848D195608F; Tue, 4 Aug 2026 07:20:27 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 14B6E300019F; Tue, 4 Aug 2026 07:20:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828031; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JBuZeH/hyIo3fbh1PQfwbL8P51yWnlk8B0Vwt9xpvUY=; b=G5Az2VB5MIeLUz208DoE2W1YV+Y8nsQd4LfXV1W8s8nkDCuBiwQepbqJi2siErYOVrwRTD qplgf73nXT5y8AgufVnr8C226Sj9bgiSBmNyS+2r996npFu35i/IWU4Zs3vf3IAmWLcxTb Qwct1MpCki0s09OtBffCDG50TFfG4JQ= X-MC-Unique: V2GN3pU_MJuAXzrr380JHQ-1 X-Mimecast-MFC-AGG-ID: V2GN3pU_MJuAXzrr380JHQ_1785828027 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:53 +0400 Subject: [GIT PULL 4/9] hw/display/virtio-gpu: fix offset wraparound in scanout_blob_to_fb MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-4-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, "Michael S. Tsirkin" , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=2466; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=FfMPC0vcyAbfCBx4BJKAkGllsY7YFmvTU8YJxb5Uii8=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdknx46SRrL+go+Q6GJlcGkJAZrSCEH0sbE PovTyIPX/yJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5XvoD/9qE/VNgE8DJ8jkyKIbgetYIt+jNWhdxAuhEh8nCkV/Qir53lxoT/0AEsBkEgM5d1Bq32W evHhqGVJNyoS8MFc6rKYiUOFtlibhpLBYTK94oRtDCegJCD36eQAii9zbwONlgEHP5g/OB86ZE2 FgE+ZeiDuCqx7Bo0HWPr3IUe54NDbdE/Vb8/cid/1k2oaLBhQn5Snpf7X8+ZDgMf8djBnVvieeN DutxeH4NmwUJpbYSZifqLcAuI5CqrjLO3plr3QKf8Rp42MuqQBSku2Ixqf034icQ5csUd12cf4U JLZzP3rpe6Xg965zrYxkqMynfYZ5N3DMwn5Jg4oc6CLQMsstNhtAaJutzmIMzNXGLPfVZ9CrO8J DurQOP59iwzafy6olKgpWabmSUkaxcYm/WORek/7bMt+J+eiV9BYLt8tksR6db2iGN5BvO/bv83 jt8LrmLAKCz+D4KUGvZLCVd0XEnjxKDXr5UTL5Jrzh34iquq4yzzfzAQhSYZXbdxze4eK2UzZvi 7OeSRSQ/pwbKGKvkG2DbOFUf3oczy7bOT18J/7T8hdB4TmufyHLMvhmrS3qtG3kCdYbriIG8a9x s4lCYKAtNLwGbmVGNnhNQaLoAJC5qxKhZDFyqmUIpMnEwenjO2ExcUBmSDW+qo8Bk8h0VZGBM4V sjl+PJ2UP+7XI+w== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828050900158500 virtio_gpu_scanout_blob_to_fb() computes the framebuffer offset from guest-controlled offsets[0], r.x, r.y and stride using uint32_t arithmetic. When the sum exceeds UINT32_MAX, silent wraparound lets the guest steer the scanout to an arbitrary in-bounds region of the blob instead of the intended rectangle. Compute the offset in uint64_t, reject values exceeding UINT32_MAX (the width of fb->offset), and only store into fb->offset once both range checks pass. ("[PATCH] hw/display/virtio-gpu: Remove the bytes_pp field") Fixes: 32db3c63ae11 ("virtio-gpu: Add virtio_gpu_set_scanout_blob") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3871 Based-on: <20260719-bpp-v1-1-9b91946d6cf3@rsg.ci.i.u-tokyo.ac.jp> Reported-by: Cyber_black Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260725122734.1775774-1-marcandre.lureau@redhat.com> --- hw/display/virtio-gpu.c | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 0206910cc377..51592b49c21e 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -777,7 +777,7 @@ bool virtio_gpu_scanout_blob_to_fb(struct virtio_gpu_fr= amebuffer *fb, struct virtio_gpu_set_scanout_blob *ss, uint64_t blob_size) { - uint64_t fbend; + uint64_t fbend, offset; uint32_t bytes_pp; =20 fb->format =3D virtio_gpu_get_pixman_format(ss->format); @@ -807,18 +807,20 @@ bool virtio_gpu_scanout_blob_to_fb(struct virtio_gpu_= framebuffer *fb, return false; } =20 - fb->offset =3D ss->offsets[0] + ss->r.x * bytes_pp + ss->r.y * fb->str= ide; + offset =3D (uint64_t)ss->offsets[0] + (uint64_t)ss->r.x * bytes_pp + + (uint64_t)ss->r.y * fb->stride; =20 - fbend =3D fb->offset; - fbend +=3D (uint64_t) fb->stride * ss->r.height; + fbend =3D offset + (uint64_t)fb->stride * ss->r.height; =20 - if (fbend > blob_size) { + if (offset > UINT32_MAX || fbend > blob_size) { qemu_log_mask(LOG_GUEST_ERROR, - "%s: fb end out of range\n", + "%s: invalid fb bounds\n", __func__); return false; } =20 + fb->offset =3D offset; + return true; } =20 --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828065; cv=none; d=zohomail.com; s=zohoarc; b=W7k/m2wQX3v9KzMWZ9K85eG3vRBqpJjVItbWKHgZx2yOvU2C4Ym6/6CgdinkjVv2pUE2PqcQVr4bf7k9kGhRSddNvyyS3v8OYFuKFY6kM/yaN5ephQutCA4Vog23nS/R46jTrMusFbRIoFbJF7I7wIDi+Qj3tX0fKR2mLKhJdEU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828065; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/YLITtyQZk/29n/Ki+VXTGedtcpRCCASc2TUbUo+E6I=; b=T51cjHAA7hyy+Gibw6jGur794txRggp1bIS4lWWd95gtXesDXERJosNXFiC7U8PH/XZz3JPJ7OCNFd/uMgLOVK6m8ons8YTrQbmP5VRe+cs1CBzMR6qC3NutskkAACm6ky/IiRd9LVhpb6GUhexND6lWmJJsN1ONbfkBNTUqTj8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828065426752.6567568817396; Tue, 4 Aug 2026 00:21:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9SJ-0002Yu-21; Tue, 04 Aug 2026 03:20:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9SD-0002M3-Ux for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:50 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9SB-0001Vo-Pk for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:49 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-122-u3HbEawpMfipLhlYryj9jA-1; Tue, 04 Aug 2026 03:20:38 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 0B50C1800623; Tue, 4 Aug 2026 07:20:34 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 88A81300019F; Tue, 4 Aug 2026 07:20:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828045; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=/YLITtyQZk/29n/Ki+VXTGedtcpRCCASc2TUbUo+E6I=; b=AkarhlSoZWc3sChrHDRKHJhUzmp+8YPw6dsu7DSX8Y4sl9wEGdzQTSXlDXlju5vQ+JNBAV Ure3M1NggRZMxGPOodHlA2MiY0rwP2SXnwUNF15qKM1+rTtuobwNkuQgq8JxLRuszm/vto hvVwPpyCNNMOEtC+WOBdIaq/ACZ3KSg= X-MC-Unique: u3HbEawpMfipLhlYryj9jA-1 X-Mimecast-MFC-AGG-ID: u3HbEawpMfipLhlYryj9jA_1785828034 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:54 +0400 Subject: [GIT PULL 5/9] hw/display/virtio-gpu: drop redundant node->value NULL checks MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-5-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko , "Michael S. Tsirkin" X-Developer-Signature: v=1; a=openpgp-sha256; l=1790; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=sjywyeADAIGro/JFp1dJCBH1U0aQQKbRC3WkRHfn7go=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdZ+qbUs7Va0TESwMg46J2DvVidvH2in6uy aH1yUKQK3yJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5UF6D/9aZUCkIydDEJyM47s7eDMJTqXBH/38424s+CWkbzvg3pSnoBQlGo3sVoRaCiO8+oQTXt5 +YFbX1oKstEn78dctW+XWjxJxrZw6SNA14W+6piRIqOoEGgZ/d28qQSas+6TNHxFbnWWbrUeqOt 8rD6Odk+Cbqg/KCBUbxUPQJaE16UXePomZ8T6Pt/5Icxs5irnyDgz69qlk/pz/SuzO2VRc+WGbQ 5O6I7uPXWF9cGN9KwFXzwB9y2Fxm0kxr8YduXkqaQ5xdUD6MOc3gSE9J0uW/DSSha58BxUjbxjd MU3qM0kgevM7ypfaN5LjHHEyoWttzp9mEMz6i4eleuDhM8SUp5sXVzJCi1x9U1Mz3Vvn5fIIZJT h3x494RnRYY3dEhF7ImWnrX+AVJz0Xk+XrjAROmYxC4sVx09+o7ksKh19ZLp4MYKBavDO56vhVZ aXK2Rcwgv60L1HmzYYDz4zX/W9KvaQthxV5isLpClo8Xi3xdBEhXdPiNBVZ74upb1FIklYfEzqj JKzG7uSF2mhMk7moiquy/gstEKSuMRa+qyOBiJuC0j25QorALLArTB8rDK8jm7Yr2TrP+Y4nyoJ n+RrSUeJ2/Aob61PacOYIqcdKXGXTnVnIxlX+hds1ibKF9hyW7kSUbxIJdnWspGJkHtASSeY1iy IJgZqlU0NGAzKCA== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -28 X-Spam_score: -2.9 X-Spam_bar: -- X-Spam_report: (-2.9 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828067353158500 QAPI-generated list visitors guarantee that node->value is never NULL: the input visitor allocates it via g_malloc0() in visit_start_struct(), and on failure the entire list parse is aborted and freed. Remove the unnecessary NULL checks from both callsites iterating g->conf.outputs. Resolves: Coverity CID 1664272 Fixes: 8dc8449a678f ("hw/display/virtio-gpu: Avoid leaking migration blocke= r") Reviewed-by: Akihiko Odaki Signed-off-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260730114751.3515083-1-marcandre.lureau@redhat.com> --- hw/display/virtio-gpu-base.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/display/virtio-gpu-base.c b/hw/display/virtio-gpu-base.c index 946e56b42f61..270fbaae1029 100644 --- a/hw/display/virtio-gpu-base.c +++ b/hw/display/virtio-gpu-base.c @@ -69,7 +69,7 @@ virtio_gpu_base_generate_edid(VirtIOGPUBase *g, int scano= ut, =20 for (output_idx =3D 0, node =3D g->conf.outputs; output_idx <=3D scanout && node; output_idx++, node =3D node->nex= t) { - if (output_idx =3D=3D scanout && node->value && node->value->name)= { + if (output_idx =3D=3D scanout && node->value->name) { info.name =3D node->value->name; break; } @@ -206,7 +206,7 @@ virtio_gpu_base_device_realize(DeviceState *qdev, error_setg(errp, "invalid outputs > %d", g->conf.max_outputs); return false; } - if (node->value && node->value->name && + if (node->value->name && strlen(node->value->name) > EDID_NAME_MAX_LENGTH) { error_setg(errp, "invalid output name '%s' > %d", node->value->name, EDID_NAME_MAX_LENGTH); --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828068; cv=none; d=zohomail.com; s=zohoarc; b=UJ6ugpR4xS9bewp7hqVUUg5YohwIjqxYo1kabkau1vvhVVPtvSVY80GDFWpnsj61gUgPF6HavrS25nFUwYBDjeks1ju/bgO/gc62IZqq8iWoCXTTTu1ZPSd3V5A8JSvDhdoJ6ZXeympcHXP2RxHFT2CFFHThLp+8CC5J9wPXuX0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828068; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=n7JJ+hcyRyV7L2E2biokXg6Kr5R0fBx2vtTrODZON80=; b=UR+qPFHLF+LYlB/DB2K6823qxWCBkpM/x3PCTlyaaSJxAOe8Zy0ouI338eMZPe7tirDkNe2AZ4DSg5mcMFdu/PnVt/r8Xf1Ne+/++/SHwosKcrHQPP/OID3x4m5zbhhp5uKj67QsTw/CcAFZublB+a19Pcyj3l7MLFmQPxS0xss= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828068692367.91622795875514; Tue, 4 Aug 2026 00:21:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9SM-0002h6-SN; Tue, 04 Aug 2026 03:20:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9SL-0002gc-2j for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:57 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9SJ-0001Wc-B4 for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:20:56 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-468-paC-8cn6P-6AlyyqpTPjIw-1; Tue, 04 Aug 2026 03:20:46 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3506719560A6; Tue, 4 Aug 2026 07:20:45 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 0D834300019F; Tue, 4 Aug 2026 07:20:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828054; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=n7JJ+hcyRyV7L2E2biokXg6Kr5R0fBx2vtTrODZON80=; b=ILkKrUlhcZ+H6ep4NTpDbvqjGNYOF98IpYxnEroyTwmPtmEtHE5jchEmmJKI1pr3I4l3+V rHllIKx1NkWlwOlnjLcXZlrtsR3dtZr3MhbQtUEwl1mjwrAcdcQGZr/nTXmZ0lXfSv//HF qMnCo4g7JossK6RMc0HI2UJywgV8Cwc= X-MC-Unique: paC-8cn6P-6AlyyqpTPjIw-1 X-Mimecast-MFC-AGG-ID: paC-8cn6P-6AlyyqpTPjIw_1785828045 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:55 +0400 Subject: [GIT PULL 6/9] virtio-gpu: reject requests with short/truncated control headers MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-6-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, "Michael S. Tsirkin" , Stefano Garzarella , =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=4438; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=jaPJDGwWA1VqGu8rJHjZKo+J8zwGDTWWnz8+PwcussU=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdkawZFC1DxpoYxe1QO3j4jERQaNl82iL4+ R5H7IVYGSWJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5VFLD/45u7rauyNFSyU5veO6KTXPT5U0Wo6ZBIFYThDa1oa0StSzSI7hEef25sHQoFilsMHvDMw rPRhcSAlhNt1aMfzN9QoSLVXBcS8UlrpKHzMkAAR3lK/7eGUdmdwg1J8iiBWEcdgsh1gCUmoVQq uXmQAUQZAdezP6sRpRUiXzajS0hl6apLzfMd4sqYCnA8p9JVQtoi969ODobn56HqB4E0tgJAivv n/wrj1Lb25bWLieXxv9PfceTVtHF2lH+JRV1e0oueTKSBm5u3y8CMbRnFJ5hn/2z2e6MxDOelc0 4Dq3EyzZZvrqnw2lN/QobsPyT/loMYRwh9mjbRVDcSBECjUqw7tr2l7d27aMkqgv/iFtOf3XHAN jn0y8c+7JfsPgOerAfQL/GKVoTlFriZqVgXhQdfqNLT3su3qdAlUT3TNrU+lKlPwSbLGBQvCT6M pWZhIKpKm5V1AFdViT3ipEjxfZJ1N/PNrnO7xXiJFD5Gee3ZaV64n7w/alpwn3l7Qh5BEGNTA5l vJpkJt2aP49w32znMFAbXKtJj3bqOL3zsaXdPR6n1Uv2yJLMkoVZOpEf2651cXMQpsk8LCquOC3 Z5qAVspbyycY19+YcnykLMLGqD7PIvPP5X2RRMEiW5xG5AsR5kI5y6N6cK39I8eBufIHSafMPfk ibz48jA+cmcGveQ== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828068925158500 From: Ankur Saini A short control request can leave command data partially initialized. For the common header, guest-controlled flags can then cause stale fence metadata to be returned to the guest. The command fill helpers detect a short copy but only log and return. For the common header this leaves the request without any completion; for type-specific commands the caller still completes the request but reports VIRTIO_GPU_RESP_OK_NODATA, masking the error. Make VIRTIO_GPU_FILL_CMD() clear the partially copied object and complete the request with ERR_INVALID_PARAMETER. Make VUGPU_FILL_CMD() report the same error through the existing vhost-user-gpu dispatcher. This also rejects truncated type-specific commands. The vhost-user-gpu common header is copied outside VUGPU_FILL_CMD(), so clear it and complete the request directly when that copy is short. Fixes: CVE-2026-66021 Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094 Reported-by: Ankur Saini Suggested-by: Akihiko Odaki Signed-off-by: Ankur Saini Reviewed-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260803-virtio-gpu-short-header-v3-1-936c1daa8e61@gmail.com> --- contrib/vhost-user-gpu/vugpu.h | 1 + include/hw/virtio/virtio-gpu.h | 3 +++ contrib/vhost-user-gpu/vhost-user-gpu.c | 21 ++++++++++++--------- 3 files changed, 16 insertions(+), 9 deletions(-) diff --git a/contrib/vhost-user-gpu/vugpu.h b/contrib/vhost-user-gpu/vugpu.h index 2374eb90cb9b..aaf2870cb24d 100644 --- a/contrib/vhost-user-gpu/vugpu.h +++ b/contrib/vhost-user-gpu/vugpu.h @@ -179,6 +179,7 @@ struct virtio_gpu_ctrl_command { if (vugpufillcmd_s_ !=3D sizeof(out)) { \ g_critical("%s: command size incorrect %zu vs %zu", \ __func__, vugpufillcmd_s_, sizeof(out)); \ + cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; \ return; \ } \ } while (0) diff --git a/include/hw/virtio/virtio-gpu.h b/include/hw/virtio/virtio-gpu.h index 2f60c72078b3..f965defa6b25 100644 --- a/include/hw/virtio/virtio-gpu.h +++ b/include/hw/virtio/virtio-gpu.h @@ -315,6 +315,9 @@ struct VirtIOGPURutabaga { qemu_log_mask(LOG_GUEST_ERROR, \ "%s: command size incorrect %zu vs %zu\n", \ __func__, virtiogpufillcmd_s_, sizeof(out)); \ + memset(&out, 0, sizeof(out)); \ + virtio_gpu_ctrl_response_nodata( \ + g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER); \ return; \ } \ } while (0) diff --git a/contrib/vhost-user-gpu/vhost-user-gpu.c b/contrib/vhost-user-g= pu/vhost-user-gpu.c index ee9858c397ce..786488150932 100644 --- a/contrib/vhost-user-gpu/vhost-user-gpu.c +++ b/contrib/vhost-user-gpu/vhost-user-gpu.c @@ -930,16 +930,19 @@ vg_handle_ctrl(VuDev *dev, int qidx) if (len !=3D sizeof(cmd->cmd_hdr)) { g_warning("%s: command size incorrect %zu vs %zu\n", __func__, len, sizeof(cmd->cmd_hdr)); - } - - virtio_gpu_ctrl_hdr_bswap(&cmd->cmd_hdr); - g_debug("%d %s\n", cmd->cmd_hdr.type, - vg_cmd_to_string(cmd->cmd_hdr.type)); - - if (vg->virgl) { - vg_virgl_process_cmd(vg, cmd); + memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr)); + vg_ctrl_response_nodata( + vg, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER); } else { - vg_process_cmd(vg, cmd); + virtio_gpu_ctrl_hdr_bswap(&cmd->cmd_hdr); + g_debug("%d %s\n", cmd->cmd_hdr.type, + vg_cmd_to_string(cmd->cmd_hdr.type)); + + if (vg->virgl) { + vg_virgl_process_cmd(vg, cmd); + } else { + vg_process_cmd(vg, cmd); + } } =20 if (cmd->state !=3D VG_CMD_STATE_FINISHED) { --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828084; cv=none; d=zohomail.com; s=zohoarc; b=Fk4itWPkr6PqIcuhjDqVFyLgVZJD79aSn8nxQA7HBYVOM8hLDpcaq815VYpFSN5tU2sDr09VNiJBkp8V+WhwN4MVWmZtV8em59FCCESFINI4DHyD5xf+XHbM1pn+xwxMyuGQYHsVeoj/G764irPwrU39VgC16d2IJriUW1+RBNU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828084; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=aULtpVcVtyCMV62+QOgZRcxVB09PF0BdgKmsWwfe87k=; b=YhVgVu5koc2c/sb+MJQJzxi0bRw0Z4tfw4Lv3HNoagl4s7H8f/UJp1sm71edfLySO55mXzS3bcWhVogI1KCUEg0uil8tNFxud9rXExN8v+FiyY6uv9lGw3+YAg9VSGMl7O14jczBA3q+wLNsF/1GJjJrz9/3jKbSDdEKiQBRKbc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828084261518.3247423891021; Tue, 4 Aug 2026 00:21:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9SZ-00037J-4j; Tue, 04 Aug 2026 03:21:11 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9SX-00031I-Hj for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:21:09 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9SU-0001XF-RT for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:21:09 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-237-cyhT4iOePwmBvpSmIOaEiw-1; Tue, 04 Aug 2026 03:20:54 -0400 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id BF54C195608E; Tue, 4 Aug 2026 07:20:53 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B57041956087; Tue, 4 Aug 2026 07:20:51 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828066; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=aULtpVcVtyCMV62+QOgZRcxVB09PF0BdgKmsWwfe87k=; b=TYeBL8bn3CbG0DeU2pcfp7Ne9bp1GjuAVDhUJ1puS98NEuTpzL0UOCU0LI86LbFIcmWMDg +6TGYRbqEsdySGwTdhpL04QTf48gmMnzLhFmLCRTt9eEG9WSdnIy7MVgoxdTsnuJ72bT1r arr8jhCAugen4Dc8Z+aJ5FgmGzX//Ug= X-MC-Unique: cyhT4iOePwmBvpSmIOaEiw-1 X-Mimecast-MFC-AGG-ID: cyhT4iOePwmBvpSmIOaEiw_1785828053 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:56 +0400 Subject: [GIT PULL 7/9] hw/display/virtio-gpu: Always reject invalid scanout bounds MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-7-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko , "Michael S. Tsirkin" X-Developer-Signature: v=1; a=openpgp-sha256; l=7071; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=lPEGPLPQO9o4Iq92ww7DSP/izILyow8FYE5uhd9yQZc=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdNehPbOYPJ7RAof/TVteawEb+DYMeuqiEn HMT57VOO/SJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5SLvD/9YtGwf3H6wzGaZuctb5OEJgHhF0Ve4wYJ4RKlWMPGRWRrPqZRgajgCfhSGDTx8Z2SxZAR Nrs7ndEUcz+uokx883j4ORQGy82CuwcwRlN3G1WGJveaQhngb9HS7BvJ7Qm7fICkwIWQdyuVAuA 8OtPzrHCkhqEFb+uxPqI08IiVSaiYqFyfWPqj6d8qomz4Ql/SakdbEwyQTvC16UdBi7Pr0uZZov hyh04SZieTPwML2lhl3WtcYzsV+Nr2T+KFBWcofMxC3ms5aAjxnu/vKQFlmBwSDjoFCp1Ok1Etx oJFYjZgJjoJrBz8ovWTfur0ggOq1nAh7GLv3SUtEWuoWb1AF0vZ9CoSjNuDq7tZdIZBMhWEvbHz pSOrcAs7NO1kJwFSgRVF2RGq8u6tfwHgbKNP01bazWOPB0TiL3Bfvdce19C6/87ATp1KHYGnIFR Ij5jJ5BrCfNqnBB0xohOFhZYXP/DVFaHmjqwy0USgqulrEDPLJ2VwwlKLzhs5BO4XJyDCGPEZIO 0bFZgabzWN0ofbuGr4Ipb1HkpuRdXZPy923K7GMK+NB9v+3anaUfm2wvCXr6D/nVI7zJngR7o5c m06l3J0lQsQvEFFFj6ZqPXmzaXR9yyvtSoUR4a10u0dxTf5DCAxTaLjy/fWVyeYUuTW5Gu/2sB4 znssjHff/nmgo9A== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 4 X-Spam_score: 0.4 X-Spam_bar: / X-Spam_report: (0.4 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828085083158500 From: Akihiko Odaki virtio-gpu does not consistently check scanout bounds with wraparound handling. In the unchecked virgl SET_SCANOUT path, guest dimensions reach qemu_console_resize(), qemu_create_displaysurface(), and ultimately qemu_pixman_image_new_shareable(..., &error_abort), so an invalid rectangle can terminate QEMU. Implement a check with proper wraparound handling and apply it consistently. Fixes: 9d9e152136bd ("virtio-gpu: add 3d mode and virgl rendering support.") Fixes: 32db3c63ae11 ("virtio-gpu: Add virtio_gpu_set_scanout_blob") Fixes: 7c092f17ccee ("virtio-gpu: Handle resource blob commands") Fixes: 1dcc6adbc168 ("gfxstream + rutabaga: add initial support for gfxstre= am") Signed-off-by: Akihiko Odaki Reviewed-by: Philippe Mathieu-Daud=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260803-scanout-v1-1-c9831dafdab2@rsg.ci.i.u-tokyo.ac.jp> --- include/hw/virtio/virtio-gpu.h | 5 +++++ hw/display/virtio-gpu-rutabaga.c | 6 ++++++ hw/display/virtio-gpu-virgl.c | 20 +++++++++----------- hw/display/virtio-gpu.c | 36 ++++++++++++++++++++++-------------- 4 files changed, 42 insertions(+), 25 deletions(-) diff --git a/include/hw/virtio/virtio-gpu.h b/include/hw/virtio/virtio-gpu.h index f965defa6b25..220231ec9d43 100644 --- a/include/hw/virtio/virtio-gpu.h +++ b/include/hw/virtio/virtio-gpu.h @@ -366,6 +366,11 @@ void virtio_gpu_update_cursor_data(VirtIOGPU *g, struct virtio_gpu_scanout *s, uint32_t resource_id); =20 +bool virtio_gpu_check_scanout_bounds(uint32_t scanout_id, uint32_t resourc= e_id, + uint32_t width, uint32_t height, + const struct virtio_gpu_rect *r, + uint32_t *error); + /** * virtio_gpu_scanout_blob_to_fb() - fill out fb based on scanout data * fb: the frame-buffer descriptor to fill out diff --git a/hw/display/virtio-gpu-rutabaga.c b/hw/display/virtio-gpu-rutab= aga.c index e28aad94eead..a054f8117f14 100644 --- a/hw/display/virtio-gpu-rutabaga.c +++ b/hw/display/virtio-gpu-rutabaga.c @@ -315,6 +315,12 @@ rutabaga_cmd_set_scanout(VirtIOGPU *g, struct virtio_g= pu_ctrl_command *cmd) res =3D virtio_gpu_find_resource(g, ss.resource_id); CHECK(res, cmd); =20 + if (!virtio_gpu_check_scanout_bounds(ss.scanout_id, ss.resource_id, + res->width, res->height, &ss.r, + &cmd->error)) { + return; + } + if (!res->image) { pixman_format_code_t pformat; pformat =3D virtio_gpu_get_pixman_format(res->format); diff --git a/hw/display/virtio-gpu-virgl.c b/hw/display/virtio-gpu-virgl.c index d9e5b0110497..6e298f997d66 100644 --- a/hw/display/virtio-gpu-virgl.c +++ b/hw/display/virtio-gpu-virgl.c @@ -560,7 +560,7 @@ static void virgl_cmd_set_scanout(VirtIOGPU *g, } g->parent_obj.enable =3D 1; =20 - if (ss.resource_id && ss.r.width && ss.r.height) { + if (ss.resource_id) { struct virgl_renderer_resource_info info; void *d3d_tex2d =3D NULL; =20 @@ -581,6 +581,11 @@ static void virgl_cmd_set_scanout(VirtIOGPU *g, cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID; return; } + if (!virtio_gpu_check_scanout_bounds(ss.scanout_id, ss.resource_id, + info.width, info.height, &ss.= r, + &cmd->error)) { + return; + } qemu_console_resize(g->parent_obj.scanout[ss.scanout_id].con, ss.r.width, ss.r.height); virgl_renderer_force_ctx_0(); @@ -987,16 +992,9 @@ static void virgl_cmd_set_scanout_blob(VirtIOGPU *g, return; } =20 - if (ss.width < 16 || - ss.height < 16 || - ss.r.x + ss.r.width > ss.width || - ss.r.y + ss.r.height > ss.height) { - qemu_log_mask(LOG_GUEST_ERROR, "%s: illegal scanout %d bounds for" - " resource %d, rect (%d,%d)+%d,%d, fb %d %d\n", - __func__, ss.scanout_id, ss.resource_id, - ss.r.x, ss.r.y, ss.r.width, ss.r.height, - ss.width, ss.height); - cmd->error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + if (!virtio_gpu_check_scanout_bounds(ss.scanout_id, ss.resource_id, + ss.width, ss.height, &ss.r, + &cmd->error)) { return; } =20 diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index 51592b49c21e..c15d4b527d0e 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -633,6 +633,26 @@ static uint32_t virtio_gpu_format_bytes_pp(pixman_form= at_code_t format) return DIV_ROUND_UP(PIXMAN_FORMAT_BPP(format), 8); } =20 +bool virtio_gpu_check_scanout_bounds(uint32_t scanout_id, uint32_t resourc= e_id, + uint32_t width, uint32_t height, + const struct virtio_gpu_rect *r, + uint32_t *error) +{ + if (r->width < 16 || + r->height < 16 || + (uint64_t)r->x + r->width > width || + (uint64_t)r->y + r->height > height) { + qemu_log_mask(LOG_GUEST_ERROR, "%s: illegal scanout %d bounds for" + " resource %d, fb %d %d, rect (%d,%d)+%d,%d\n", + __func__, scanout_id, resource_id, width, height, + r->x, r->y, r->width, r->height); + *error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + return false; + } + + return true; +} + static bool virtio_gpu_do_set_scanout(VirtIOGPU *g, uint32_t scanout_id, struct virtio_gpu_framebuffer *fb, @@ -646,20 +666,8 @@ static bool virtio_gpu_do_set_scanout(VirtIOGPU *g, =20 scanout =3D &g->parent_obj.scanout[scanout_id]; =20 - if (r->x > fb->width || - r->y > fb->height || - r->width < 16 || - r->height < 16 || - r->width > fb->width || - r->height > fb->height || - r->x + r->width > fb->width || - r->y + r->height > fb->height) { - qemu_log_mask(LOG_GUEST_ERROR, "%s: illegal scanout %d bounds for" - " resource %d, rect (%d,%d)+%d,%d, fb %d %d\n", - __func__, scanout_id, res->resource_id, - r->x, r->y, r->width, r->height, - fb->width, fb->height); - *error =3D VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; + if (!virtio_gpu_check_scanout_bounds(scanout_id, res->resource_id, + fb->width, fb->height, r, error))= { return false; } =20 --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828093; cv=none; d=zohomail.com; s=zohoarc; b=CRz1mq99AwFs2ZoVPLUKbO6MQ5ZyBXGwkhmVDot0g8p8NdVdt7z53Gk1FsItGmXNkSK4I5fPss0v/5rqQbXQu8dsXA11Z4W2zWOrRs4ls9IJ5mTQrBTq2+gy+X8Akkhkc0+vZao2OrkL7ZIg5I4CC+fMNesW5cw+NN2RFpv9lXA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828093; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=xLTgyxY9t4cPAN5vmpA9Vq9M1u5pAtCooxqyWOTxbao=; b=V8XKC7fFA+r9A4HU8BlQlpVU3mwnLNOtoazG+ILVSLDhEll0oJSNEWZasWcBlIJ0KfFvcB9zg8EEC3UY+vmG78cUdg4+I8Tw2NrGN89mxODQ8rUjnRZjKuKdOgGytTYUDQLWbTBfpDTfuLH3xmYGS8kRe0nXnCugSz6NgaUtUq4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828093092173.8242699026398; Tue, 4 Aug 2026 00:21:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9Sf-00039K-GE; Tue, 04 Aug 2026 03:21:17 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Sd-00038u-QJ for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:21:15 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Sc-0001Xr-9h for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:21:15 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-79-KMuBmVa-OH-SNGqKmrnzdg-1; Tue, 04 Aug 2026 03:21:12 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id EDD76180057E; Tue, 4 Aug 2026 07:21:10 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2124C300019F; Tue, 4 Aug 2026 07:21:03 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828073; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=xLTgyxY9t4cPAN5vmpA9Vq9M1u5pAtCooxqyWOTxbao=; b=D/I9UexnAPi6P+D408b41ij2nE9zjoHcH9PXI/kFGURhCaFXACvjE9j8fPYlXJKOqTYJ1H sCbaaIV6VnSQhtJtfTJqNammleKKp5/9C/15Wjn/3x2Dp0Y+jnFrnQEt0swpBFHo9zjEOf Jih7oPxFF0b6z7z1wd9cOpKk82Gga2w= X-MC-Unique: KMuBmVa-OH-SNGqKmrnzdg-1 X-Mimecast-MFC-AGG-ID: KMuBmVa-OH-SNGqKmrnzdg_1785828071 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:57 +0400 Subject: [GIT PULL 8/9] hw/display/virtio-gpu: Unmap DMA regions on reset MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-8-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, "Michael S. Tsirkin" , =?utf-8?q?Alex_Benn=C3=A9e?= , Akihiko Odaki , Dmitry Osipenko X-Developer-Signature: v=1; a=openpgp-sha256; l=1303; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=6pt76Ocwcwq2ZkN5Bq1JB7UBUtXQ0SHmKMc3+x+kQHk=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdNRcM6gwc/02TQ5MnL7EqesJaJTc4FZjce eijx5SXGGSJAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5blqD/sH6Ugjs7DIopypDFg65ZZYjhtolONc3d6qo2q4BXMQm+rRVW6eAEuQRKlTnfz3D610YXV j+JLjBrzp/K5rIcPgQVk6/EJnJ/OC5+V2L43tr3krqPVfdsostn1J2/hzN7DQDYrvez5PIAOhBT ShD7q9lo5fGjNgKexuwrRjwe4fwP+XW4GPqwoKOR81wHO/8MwR+3geo7xgnzELejK+W1m8VcpQG 4Dur7F9D22iH70mgwvVPswAXWPRxmcn7uH7mpZ/k8+hJ95z28Cs8Ug2kMQBJZMKMTXMyB+ENvpk 5bXyyFY2D/sc2Khmgp8DMSDH5WuF2cEjF2/HEshyut3k/xnt3zE5V6cATknIOT2fwno1VMBH+TS K4yMp+lyLiJ+VusBw+4M7bc3Qj7mAgb4g046hm250L8xSsu4V5ksQMllOdQVS4RZpQvPIcXo1zR lTzUojlAv8oSx5iF/e3rhIcz/McTuXJq76gYMQ9DACKNhQmqLYYDARUCZcS99iArOICxG0GOG0V WM/1hSgjzJuFgp5TxgUPpZJ1w0Rmt5ryzjYLwNiViYBxuNYz8L7Qdh7kWM1/qvSr2IH/vG3Hcax PHIH//ZwF0lB4i6k2uBVCH5QP2I5wn+V+LleHHqX1yk4ARFVDkDAL1BGK99xTPQ07Uy/ieSihPc aMBSJ/E0fePUI+Q== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -28 X-Spam_score: -2.9 X-Spam_bar: -- X-Spam_report: (-2.9 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828095172158500 From: Bin Guo virtio_gpu_reset() freed in-flight commands without unmapping the DMA regions acquired by virtqueue_pop(). Call virtqueue_detach_element() before g_free() in both drain loops. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3467 Cc: qemu-stable@nongnu.org Signed-off-by: Bin Guo Reviewed-by: Akihiko Odaki Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260803082158.62998-1-guobin@linux.alibaba.com> --- hw/display/virtio-gpu.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c index c15d4b527d0e..fbb6fec7a0ad 100644 --- a/hw/display/virtio-gpu.c +++ b/hw/display/virtio-gpu.c @@ -1725,12 +1725,14 @@ void virtio_gpu_reset(VirtIODevice *vdev) while (!QTAILQ_EMPTY(&g->cmdq)) { cmd =3D QTAILQ_FIRST(&g->cmdq); QTAILQ_REMOVE(&g->cmdq, cmd, next); + virtqueue_detach_element(cmd->vq, &cmd->elem, 0); g_free(cmd); } =20 while (!QTAILQ_EMPTY(&g->fenceq)) { cmd =3D QTAILQ_FIRST(&g->fenceq); QTAILQ_REMOVE(&g->fenceq, cmd, next); + virtqueue_detach_element(cmd->vq, &cmd->elem, 0); g->inflight--; g_free(cmd); } --=20 2.55.0 From nobody Wed Aug 26 05:53:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785828095; cv=none; d=zohomail.com; s=zohoarc; b=ZVmDXEbKqmWGRPDgUDg4yMBl+1LB2R8ckV8F9PLpdv6pgBUQFRanchopK0Uwjol2jPXwE0XKBOWHx4ySufOOyzsoTFGqaeHAjGGGvZ/H8u2qzJyOUQ84yS44NDVsPvz82sY7NdQ6oegf5ztAwdmsti67DR0c+MyLTVd87torhok= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828095; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=l+5DIBFkHj3MpvRH+EMQbVA7d1EFloNPTRZrCzMHzlM=; b=JYP1Q2UcfqadxCpsFxDquB3qClUrFFabJW2g31CRbvvwf3EDQ1hvcnY7D+5UA/HhBazYaENUPUFU4M9vH+DHqkMWczr5hxMVKHiWiBUZRPC891j8ndiYgmBTpLpjzeIpQlus8TCa+BDCXnvGexnQQBOg/Hty1KnDnrwhxq4JIEc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785828095596351.9622189945494; Tue, 4 Aug 2026 00:21:35 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9Su-0003vB-MO; Tue, 04 Aug 2026 03:21:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Sr-0003jW-ON for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:21:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9Sp-0001YU-DB for qemu-devel@nongnu.org; Tue, 04 Aug 2026 03:21:28 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-82-Li71nkCSN3mPwEw_IRbG3A-1; Tue, 04 Aug 2026 03:21:20 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D140B18002C1 for ; Tue, 4 Aug 2026 07:21:19 +0000 (UTC) Received: from localhost (unknown [10.44.22.2]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 280BB414; Tue, 4 Aug 2026 07:21:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785828086; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=l+5DIBFkHj3MpvRH+EMQbVA7d1EFloNPTRZrCzMHzlM=; b=TGvP3fEKO0Wn5ZtDJF1BQ7hWwqv9qqylmQ0H74Se6OC7foY7fuUf/As2/NUD+JfMzCBweN qTLJQZrDa5iiG56qNrJL0P03n/dYSupJbLVZBc8p9tXoTjkFeicMNITNJehTQg+2MF/h6h 5I3C/EF0oI2hywyph7NRhF4uXWSR0IA= X-MC-Unique: Li71nkCSN3mPwEw_IRbG3A-1 X-Mimecast-MFC-AGG-ID: Li71nkCSN3mPwEw_IRbG3A_1785828080 From: =?utf-8?q?Marc-Andr=C3=A9_Lureau?= Date: Tue, 04 Aug 2026 11:18:58 +0400 Subject: [GIT PULL 9/9] qapi/dump: add allowed-by-guest feature to win-dmp MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260804-fix-v1-9-0c2be5390809@redhat.com> References: <20260804-fix-v1-0-0c2be5390809@redhat.com> In-Reply-To: <20260804-fix-v1-0-0c2be5390809@redhat.com> To: qemu-devel@nongnu.org Cc: stefanha@redhat.com, =?utf-8?q?Marc-Andr=C3=A9_Lureau?= , Ani Sinha , Eric Blake , Markus Armbruster X-Developer-Signature: v=1; a=openpgp-sha256; l=2712; i=marcandre.lureau@redhat.com; h=from:subject:message-id; bh=MW7OVd74nIo16HSj5Bdl5yYs6LiN+vBhp4QxuK4O7gg=; b=owEBbQKS/ZANAwAKAdro4Ql1lpzlAcsmYgBqcZJdSnIKZEBAgwjQMKcPRjfnS6V8k/18qyDdl McuO2bHbc6JAjMEAAEKAB0WIQSHqb2TP4fGBtJ29i3a6OEJdZac5QUCanGSXQAKCRDa6OEJdZac 5dwhD/45DFJTe3wdxqWfQIlpj8AjCOQ5uxpBvPjgRgNTWkKD3cOR8XX3///OtrObWzuDuvrXoau j2Qqa5H1OWlmb0Oga76/6ElxcCLeQ3EVIypBdyMe3ktqYecR4kHuVwS2YUdvu7YA/4yRuCiZZjl k0qVMieIyf/ooc6UqDc9yzu1Ri3paRYbohu9puN7OQjTn/Eryw4xMq/CuJun9ga29BILMNzUaWl XWq9W96DTDD2eHQkeusWIlwDd6OrqndBQUOb7kB6ikQLfoF7Z5yA7XXx8WsuK3bin7OMPUJHBS1 GL93VoOoMYJ7g7ABxkoJAqAUMtvolOrQYcZvNC01zzt0tfgYXhFgucTV124sHF/fSLEPPpayAU2 lSdsCjAd2iLAeQD+InCFbi4vmd7x/I03Tjvm4a7ullbqZhxCjnzS4Mh7MT8zTTBbatQzFAUSWUy cclphtzDVceLCOKyz8eAA+cjwfmHz3GHehZJARxi6yCvX50cWjRxOBU7hyq5OmQ/b7C6IYnIW3U mduOAT9CpTj0eDw0xc6Ab98JmzGREmXlU2jAUL0v696x2cjtMQAHlicMFIn8Cltg/6v/FJMXvZZ gmAaCAfvv6tif277CCgN1YOJDXPR0Qg+PdNc0bYaOwGZtzmFLo81OCW4/FxaC0Ep083WCkP4BBY CQdSwiQRD2xrF4g== X-Developer-Key: i=marcandre.lureau@redhat.com; a=openpgp; fpr=87A9BD933F87C606D276F62DDAE8E10975969CE5 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=marcandre.lureau@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -28 X-Spam_score: -2.9 X-Spam_bar: -- X-Spam_report: (-2.9 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.811, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785828097143158500 From: "Denis V. Lunev" Commit 1c0e259c5a35 ("dump: make win_dump_available() check vmcoreinfo for a Windows dump header") changed two things in a way that is visible to QMP clients but not to introspection: query-dump-guest-memory-capability now lists win-dmp only for a guest that has published a Windows dump header through the vmcoreinfo device, and dump-guest-memory, which shares win_dump_available(), rejects the format otherwise. Before that, both accepted win-dmp on any x86 machine. A client that wants to select win-dmp automatically therefore cannot trust the capability query on its own: on an older QEMU it reports win-dmp for every x86 guest, Linux ones included, where the resulting dump is useless. libvirt ran into exactly this while picking a format for on_crash and watchdog triggered dumps, and has no way to tell the two behaviours apart. Add an 'allowed-by-guest' feature to the win-dmp member of DumpGuestMemoryFormat so the fixed behaviour becomes discoverable. DumpGuestMemoryFormat is reachable from both query-dump-guest-memory-capability's return type and dump-guest-memory's arguments, so a single flag covers both halves of the change. Where the feature is absent, a reported win-dmp says nothing about the guest, and a client that needs the dump to be loadable afterwards should fall back to elf. CC: Eric Blake CC: Markus Armbruster CC: "Marc-Andr=C3=A9 Lureau" Suggested-by: Daniel P. Berrang=C3=A9 Signed-off-by: Denis V. Lunev Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Marc-Andr=C3=A9 Lureau Message-ID: <20260731155001.1204103-1-den@openvz.org> --- qapi/dump.json | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/qapi/dump.json b/qapi/dump.json index 726b5208703c..690f3963fe15 100644 --- a/qapi/dump.json +++ b/qapi/dump.json @@ -38,6 +38,13 @@ # @win-dmp: Windows full crashdump format, can be used instead of ELF # converting (since 2.13) # +# Features: +# +# @allowed-by-guest: If present, @win-dmp is listed by +# `query-dump-guest-memory-capability`, and accepted by +# `dump-guest-memory`, only when the guest has published a Windows +# dump header through the vmcoreinfo device (since 11.1) +# # Since: 2.0 ## { 'enum': 'DumpGuestMemoryFormat', @@ -45,7 +52,7 @@ 'elf', 'kdump-zlib', 'kdump-lzo', 'kdump-snappy', 'kdump-raw-zlib', 'kdump-raw-lzo', 'kdump-raw-snappy', - 'win-dmp' ] } + { 'name': 'win-dmp', 'features': ['allowed-by-guest'] } ] } =20 ## # @dump-guest-memory: --=20 2.55.0