From nobody Mon Aug 24 19:01:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1785828928; cv=none; d=zohomail.com; s=zohoarc; b=ca51yWNClqUEIGqbhDfvqN0ZgB+hci5apI9//+YvrEPy/j+mWKAhXXcYVBjEETg2iklgG1eGxE4TE1JGyrb0fpDsLHFABl0TyzzFPzWNOnZEBqN1qKSma+20wdaoXHwq+KB08ykVHqctKZVn0COlYJhVh1a+snTfFks+Jeka0Ng= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785828928; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=ghYyasCtF8FEQCbtw+bhe9K0ie0uWwUdVzgB8nhIMt4=; b=Hv0dTPk2whoukb+TFDI0FWgaqHe0LLlQ7tiuSXvrUJPkafcjJq1fJI1AJxT1H6e76JnycvGv0SmmJN2Uay7DkqWpKVfhsb6dV6pkqwFYcdleTPECoU3ns+pDhGC/3rT9+hg7B5q6uT9fCs7DOes8HOhVPJ2YvJlSrbh1c69VIdM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178582892802022.427669741273007; Tue, 4 Aug 2026 00:35:28 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wr9gA-0007hj-VK; Tue, 04 Aug 2026 03:35:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9g7-0007hN-Dv; Tue, 04 Aug 2026 03:35:11 -0400 Received: from [115.124.30.112] (helo=out30-112.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wr9g1-0002XS-LT; Tue, 04 Aug 2026 03:35:11 -0400 Received: from localhost(mailfrom:guobin@linux.alibaba.com fp:SMTPD_---0X8N7IzC_1785828886 cluster:ay36) by smtp.aliyun-inc.com; Tue, 04 Aug 2026 15:34:47 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1785828888; h=From:To:Subject:Date:Message-ID:MIME-Version; bh=ghYyasCtF8FEQCbtw+bhe9K0ie0uWwUdVzgB8nhIMt4=; b=Jvur6lQND80tFPB9eirgCuT1bjh1PJ/yUYap5aFsajHcI8CYGNqzeorLngAW92DJcHjKvas06atpVg4U9GhWBnI0ECT/PiRg1Ky5X/ilvW79LRAlC7uuyNPGxXEBuF1h0H52aiRqeMGIMTFl4oJngH5MGyByKQbAw4w9NiZdYU0= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R191e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037026112; MF=guobin@linux.alibaba.com; NM=1; PH=DS; RN=6; SR=0; TI=SMTPD_---0X8N7IzC_1785828886; From: Bin Guo To: qemu-devel@nongnu.org Cc: Song Gao <17746591750@163.com>, Bibo Mao , Xianglai Li , Jiaxun Yang , qemu-stable@nongnu.org Subject: [PATCH] hw/intc/loongarch_pch_pic: Validate htmsi_vector before indexing parent_irq Date: Tue, 4 Aug 2026 15:34:45 +0800 Message-ID: <20260804073445.55612-1-guobin@linux.alibaba.com> X-Mailer: git-send-email 2.50.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.112 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.112; envelope-from=guobin@linux.alibaba.com; helo=out30-112.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1785828930383158500 Content-Type: text/plain; charset="utf-8" pch_pic_update_irq() used the guest-writable htmsi_vector[irq] value as an index into parent_irq[] without checking bounds. A value >=3D irq_num (64 = in the array, but only 32 are used by the virt machine) causes an out-of-bounds read and a guest-triggerable QEMU crash. Validate the vector before calling qemu_set_irq() in both the raise and low= er paths and log a guest error if it is out of range. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4114 Cc: qemu-stable@nongnu.org Signed-off-by: Bin Guo Reviewed-by: Bibo Mao --- hw/intc/loongarch_pch_pic.c | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/hw/intc/loongarch_pch_pic.c b/hw/intc/loongarch_pch_pic.c index 82e16be391..e87c7497c1 100644 --- a/hw/intc/loongarch_pch_pic.c +++ b/hw/intc/loongarch_pch_pic.c @@ -19,13 +19,21 @@ static void pch_pic_update_irq(LoongArchPICCommonState = *s, uint64_t mask, { uint64_t val; int irq; + uint8_t vector; =20 if (level) { val =3D mask & s->intirr & ~s->int_mask; if (val) { irq =3D ctz64(val); + vector =3D s->htmsi_vector[irq]; + if (vector >=3D s->irq_num) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: htmsi_vector[%d]=3D%u out of range\n", + __func__, irq, vector); + return; + } s->intisr |=3D MAKE_64BIT_MASK(irq, 1); - qemu_set_irq(s->parent_irq[s->htmsi_vector[irq]], 1); + qemu_set_irq(s->parent_irq[vector], 1); } } else { /* @@ -35,8 +43,15 @@ static void pch_pic_update_irq(LoongArchPICCommonState *= s, uint64_t mask, val =3D mask & s->intisr & ~s->intirr; if (val) { irq =3D ctz64(val); + vector =3D s->htmsi_vector[irq]; + if (vector >=3D s->irq_num) { + qemu_log_mask(LOG_GUEST_ERROR, + "%s: htmsi_vector[%d]=3D%u out of range\n", + __func__, irq, vector); + return; + } s->intisr &=3D ~MAKE_64BIT_MASK(irq, 1); - qemu_set_irq(s->parent_irq[s->htmsi_vector[irq]], 0); + qemu_set_irq(s->parent_irq[vector], 0); } } } --=20 2.50.1 (Apple Git-155)