Re: [PATCH] virtio-gpu: reject requests with short/truncated control headers

Ankur Saini <[email protected]>
Newsgroups gmane.comp.emulators.qemu
Message-ID <CAE+rwONJvzJnxrrkz9Wi_5E+M6-Vq=-45B7T+guF_iJMzoza9A@mail.gmail.com>
Thanks. I found the similar path in contrib/vhost-user-gpu and will include
a minimal fix for that in v2.

On Wed, Jul 29, 2026 at 1:22 AM Akihiko Odaki <[email protected]>
wrote:

> On 2026/07/28 23:16, Ankur Saini wrote:
> > A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> > partially initialized. If the supplied bytes set the fence flag, stale
> > fence metadata may later be returned to the guest.
> >
> > Validate the common header length before dispatch. Clear cmd_hdr and
> > complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> > cannot reach the response.
> >
> > Fixes: CVE-2026-18054
> > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
> > Reported-by: Ankur Saini <[email protected]>
> > Signed-off-by: Ankur Saini <[email protected]>
>
> Reviewed-by: Akihiko Odaki <[email protected]>
>
> Please also fix vhost-user-gpu.
>
> Regards,
> Akihiko Odaki
>
> > ---
> > A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
> > partially initialized. If the supplied bytes set the fence flag, stale
> > fence metadata may later be returned to the guest.
> >
> > Validate the common header length before dispatch. Clear cmd_hdr and
> > complete malformed requests with ERR_INVALID_PARAMETER so stale fields
> > cannot reach the response.
> > ---
> >   hw/display/virtio-gpu.c | 10 ++++++++--
> >   1 file changed, 8 insertions(+), 2 deletions(-)
> >
> > diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
> > index 4d46a4eb10..15a845eff6 100644
> > --- a/hw/display/virtio-gpu.c
> > +++ b/hw/display/virtio-gpu.c
> > @@ -1105,8 +1105,14 @@ void virtio_gpu_process_cmdq(VirtIOGPU *g)
> >               break;
> >           }
> >
> > -        /* process command */
> > -        vgc->process_cmd(g, cmd);
> > +        if (unlikely(iov_size(cmd->elem.out_sg, cmd->elem.out_num) <
> > +                     sizeof(cmd->cmd_hdr))) {
> > +            memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
> > +            virtio_gpu_ctrl_response_nodata(
> > +                g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
> > +        } else {
> > +            vgc->process_cmd(g, cmd);
> > +        }
> >
> >           /* command suspended */
> >           if (!cmd->finished && !(cmd->cmd_hdr.flags &
> VIRTIO_GPU_FLAG_FENCE)) {
> >
> > ---
> > base-commit: 299e7557ed15a9a325620698add379a3ce2d1d95
> > change-id: 20260728-virtio-gpu-short-header-476aa1dae4f7
> >
> > Best regards,
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.