From nobody Sat Sep 26 20:51:41 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=baidu.com ARC-Seal: i=1; a=rsa-sha256; t=1789129532; cv=none; d=zohomail.com; s=zohoarc; b=YGHIos64BDhDS9LM5foOi2Nl6dXCU789dEfXy+/sulFOs6Kz/2IDLO+N8DfQJQ1CgyGvCTbPk8RoEYqvYNVSF6XqbRmTNY+lvJ3yeQ2MFP7XjmBY2HWuyYj9fFe+rvlepfaiabuD7XlvFMB7XPj9RObEg9eiD12gSWVsegGZ/vI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789129532; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NestDftSsnUYTgU67bOf5rFPh02N75F3TDKyOEZraYE=; b=DWK11SUuM4M/qhy68SvZNKobsDiTx3+2vUeCf3PPOH0LtCLXvmh+w32FkWwoUsnQZXGcHEWNXuxY8WhgFTZlgiJdFTTzbayKQQghhYv9T+V0F8/SO6d31VjsmDOsJByqoy9+r1caPGuTIK0El7a1zSYS5b1jsV+R5PrxVTAt4w8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789129531386608.1237754627574; Fri, 11 Sep 2026 05:25:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x50J4-0001wE-BO; Fri, 11 Sep 2026 08:24:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4wRR-0006MO-PC for qemu-devel@nongnu.org; Fri, 11 Sep 2026 04:17:02 -0400 Received: from mx24.baidu.com ([111.206.215.185] helo=outbound.baidu.com) by eggs.gnu.org with smtp (Exim 4.90_1) (envelope-from ) id 1x4wRM-0007en-Gl for qemu-devel@nongnu.org; Fri, 11 Sep 2026 04:17:01 -0400 X-MD-Sfrom: lirongqing@baidu.com X-MD-SrcIP: 172.31.50.47 From: lirongqing To: =?UTF-8?q?Eugenio=20P=C3=A9rez?= , "Michael S . Tsirkin" , Stefano Garzarella , CC: Li RongQing Subject: [PATCH] vhost: fix off-by-one in vhost_svq_next_desc with IN_ORDER Date: Fri, 11 Sep 2026 16:16:35 +0800 Message-ID: <20260911081635.1872-1-lirongqing@baidu.com> X-Mailer: git-send-email 2.17.1 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Originating-IP: [10.127.73.8] X-ClientProxiedBy: bjkjy-exc7.internal.baidu.com (172.31.50.51) To bjkjy-exc3.internal.baidu.com (172.31.50.47) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=baidu.com; s=selector1; t=1789114603; bh=NestDftSsnUYTgU67bOf5rFPh02N75F3TDKyOEZraYE=; h=From:To:CC:Subject:Date:Message-ID:Content-Type; b=XBtaI3+fdgWXl+A5iRJn6t9C7k4LY7Bh7PKVeAsI7EePZV5Uv3VA+EMxUJ+yV6YAn CEFZutNKtvi0TynCZTJdGSvqZkld0OAqZVLM4HzPhyrN7vpGTTK/f41LLvRT83kPJT RpC4B7ZMgkesAMWNx0xUzqJOwiQXA7ispz5TK59D4u70zSEIVFmh38VQk5WpfAHDnD ECpLgkAqlQWN54B2G3m/fYGDE5VUpenlBCSqB7cKVBa+1uUkKBDigZjsavldeBagpK BNoAKH0sOT8eH12XqxiRa6STN7y+KxfPRgxz87c4u2p47/f6EsUYGfjZqKFICtnazr FfT3NgPqjo0AA== Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=111.206.215.185; envelope-from=prvs=md17080B843A=lirongqing@baidu.com; helo=outbound.baidu.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Fri, 11 Sep 2026 08:24:34 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @baidu.com) X-ZM-MESSAGEID: 1789129540117158500 From: Li RongQing vhost_svq_next_desc checks id against vring.num before incrementing, so when id =3D=3D vring.num - 1 the function returns vring.num instead of 0. This causes vhost_svq_vring_write_descs to write descs[num-1].next =3D num (an invalid descriptor index) and, on the next iteration, to access descs[num] =E2=80=94 which lies past the descriptor ring and into the avail ring, corrupting it. The bug triggers whenever an IN_ORDER descriptor chain wraps around the end of the SVQ ring. Fix by incrementing id first, then checking for wrap-around. Fixes: 485c9e69ef6e ("vhost: add in_order feature to shadow virtqueue") Signed-off-by: Li RongQing --- hw/virtio/vhost-shadow-virtqueue.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/virtio/vhost-shadow-virtqueue.c b/hw/virtio/vhost-shadow-vi= rtqueue.c index 9404762..d4f5299 100644 --- a/hw/virtio/vhost-shadow-virtqueue.c +++ b/hw/virtio/vhost-shadow-virtqueue.c @@ -155,7 +155,7 @@ static uint16_t vhost_svq_next_desc(const VhostShadowVi= rtqueue *svq, uint16_t id) { if (virtio_vdev_has_feature(svq->vdev, VIRTIO_F_IN_ORDER)) { - return (id =3D=3D svq->vring.num) ? 0 : ++id; + return (++id =3D=3D svq->vring.num) ? 0 : id; } else { return svq->desc_state[id].next; } --=20 2.9.4