From nobody Sat Sep 26 20:50:32 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linux.alibaba.com ARC-Seal: i=1; a=rsa-sha256; t=1789550676; cv=none; d=zohomail.com; s=zohoarc; b=e6hrpCCuXKxodw9JU9oVz2Sp2J84w0WmYcIKmKQjCn4BYre97oMi/nUoUL4AqT3vux0jsgQroxIlAZc9pWLJmBC6scMSyma433aowuf2WIjIQojc/xIchyCGvopb9m46LNE4k+zGItcS15iF9FA39h44Yo4JmAA1MBd4NmjdfkE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789550676; h=Content-Transfer-Encoding:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=TzcpWbB/mywt4qFXfS07N55BJh8v9Pgt50EmE+fPLd4=; b=GPvuVVOy/pzasb+NyKKHRG1Yc5WSiHaHhayU6Ll/Q0mHcIST+gY781h92WfQRZ0R+o8bSmbR70VMXX1Utv2FJ5rIZagzO+BEiD1Qy0HPN5TG9p+zubblCnkxRWx66Uj3Y+hvTuukgon7LCnEzgRujS9n7a8V2aYU5nxmngG83aI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789550676846613.322526607931; Wed, 16 Sep 2026 02:24:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6lsG-0000pV-Ho; Wed, 16 Sep 2026 05:24:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6lsC-0000ol-Ji for qemu-devel@nongnu.org; Wed, 16 Sep 2026 05:24:12 -0400 Received: from [115.124.30.118] (helo=out30-118.freemail.mail.aliyun.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6ls8-0000vq-6o for qemu-devel@nongnu.org; Wed, 16 Sep 2026 05:24:12 -0400 Received: from localhost(mailfrom:guobin@linux.alibaba.com fp:SMTPD_---0XB4b6Di_1789550623 cluster:ay36) by smtp.aliyun-inc.com; Wed, 16 Sep 2026 17:23:43 +0800 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.alibaba.com; s=default; t=1789550624; h=From:To:Subject:Date:Message-ID:MIME-Version; bh=TzcpWbB/mywt4qFXfS07N55BJh8v9Pgt50EmE+fPLd4=; b=L1oLS2nrBjh44SxaahHoNlbqkiSHlOFr8y9zNHud6MsLEKvAeVIqOgtE7+dUEN9ZhZfbVa0764mUV6eMeCdQlVcM9Lq3uk8FD7v+h8o7ldtvptORwpg5gNVi3o7Vg7n/jnJYbML6UEZpYhLm2d19SZbZUVKPSHi8EcCvA1ESMRI= X-Alimail-AntiSpam: AC=PASS; BC=-1|-1; BR=01201311R761e4; CH=green; DM=||false|; DS=||; FP=0|-1|-1|-1|0|-1|-1|-1; HT=maildocker-contentspam033037033178; MF=guobin@linux.alibaba.com; NM=1; PH=DS; RN=1; SR=0; TI=SMTPD_---0XB4b6Di_1789550623; From: Bin Guo To: qemu-devel@nongnu.org Subject: [PATCH] hw/usb/u2f: validate ring buffer indices on migration load Date: Wed, 16 Sep 2026 17:23:42 +0800 Message-ID: <20260916092342.2447-1-guobin@linux.alibaba.com> X-Mailer: git-send-email 2.50.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Host-Lookup-Failed: Reverse DNS lookup failed for 115.124.30.118 (deferred) Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=115.124.30.118; envelope-from=guobin@linux.alibaba.com; helo=out30-118.freemail.mail.aliyun.com X-Spam_score_int: -166 X-Spam_score: -16.7 X-Spam_bar: ---------------- X-Spam_report: (-16.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, RDNS_NONE=0.793, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linux.alibaba.com) X-ZM-MESSAGEID: 1789550680089158500 Content-Type: text/plain; charset="utf-8" The U2F key pending_in ring buffer uses uint8_t start/end/num indices over a 32-entry array, all serialized in the vmstate. A malicious migration stream can inject values >=3D U2FHID_PENDING_IN_NUM (32), causing an out-of-bounds heap read in u2f_pending_in_get() on the first USB IN token after migration completes. Add a post_load callback to validate the restored indices and reset the ring buffer to empty on any out-of-range value. Pending packets are non-critical (the device will regenerate them), so resetting the ring is preferable to rejecting migration entirely. As defense-in-depth, also add a bounds clamp in u2f_pending_in_get() so that even if corrupted state somehow reaches the consumer path, the index is folded into range before array access. Resolves: https://gitlab.com/qemu-project/qemu/-/issues/4483 Signed-off-by: Bin Guo --- hw/usb/u2f.c | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/hw/usb/u2f.c b/hw/usb/u2f.c index d6291852f6..9ca9879f3e 100644 --- a/hw/usb/u2f.c +++ b/hw/usb/u2f.c @@ -228,6 +228,11 @@ static uint8_t *u2f_pending_in_get(U2FKeyState *key) return NULL; } =20 + /* Clamp to valid range in case of corrupted state (e.g. migration) */ + if (key->pending_in_start >=3D U2FHID_PENDING_IN_NUM) { + key->pending_in_start %=3D U2FHID_PENDING_IN_NUM; + } + index =3D key->pending_in_start; key->pending_in_start =3D (index + 1) % U2FHID_PENDING_IN_NUM; --key->pending_in_num; @@ -301,10 +306,36 @@ static void u2f_key_realize(USBDevice *dev, Error **e= rrp) key->ep =3D usb_ep_get(dev, USB_TOKEN_IN, 1); } =20 +static int u2f_key_post_load(void *opaque, int version_id) +{ + U2FKeyState *key =3D opaque; + + /* + * Validate pending_in ring buffer indices restored from the migration + * stream. An attacker-controlled stream could inject values >=3D 32 + * (U2FHID_PENDING_IN_NUM), causing out-of-bounds heap access in + * u2f_pending_in_get() on the first IN token after migration. + * + * Reset the ring on any invalid value: pending packets are non-critic= al + * (they will be regenerated by the device), so rejecting migration + * entirely is not necessary. + */ + if (key->pending_in_start >=3D U2FHID_PENDING_IN_NUM || + key->pending_in_end >=3D U2FHID_PENDING_IN_NUM || + key->pending_in_num > U2FHID_PENDING_IN_NUM) { + key->pending_in_start =3D 0; + key->pending_in_end =3D 0; + key->pending_in_num =3D 0; + } + + return 0; +} + const VMStateDescription vmstate_u2f_key =3D { .name =3D "u2f-key", .version_id =3D 1, .minimum_version_id =3D 1, + .post_load =3D u2f_key_post_load, .fields =3D (const VMStateField[]) { VMSTATE_USB_DEVICE(dev, U2FKeyState), VMSTATE_UINT8(idle, U2FKeyState), --=20 2.50.1 (Apple Git-155)