Re: [PATCH v3] hw/display/virtio-gpu: validate blob iov size

Akihiko Odaki <[email protected]>
Newsgroups gmane.comp.emulators.qemu
Message-ID <[email protected]>
On 2026/07/30 1:14, [email protected] wrote:
> From: Marc-André Lureau <[email protected]>
> 
> virtio_gpu_resource_create_blob() stores the guest-controlled blob_size
> without checking it against the total size of the iov backing entries.
> Since both values are independently guest-controlled, a malicious guest
> can set blob_size much larger than the actual iov backing. Subsequent
> SET_SCANOUT_BLOB checks bounds against the inflated blob_size, allowing
> a pixman surface to be created over the undersized buffer. Any display
> refresh then reads past the actual allocation, potentially crashing
> QEMU or leaking host memory contents depending on the backing type.
> 
> Validate that the iov backing is at least as large as the declared
> blob_size in create_blob (when nr_entries > 0, since the spec permits
> deferred backing), attach_backing (when attaching to a blob resource),
> and the blob migration load path.
> 
> Fixes: CVE-2026-66021
> Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob")
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3945
> Reported-by: "sundayjiang(蒋浩天)" <[email protected]>
> Signed-off-by: Marc-André Lureau <[email protected]>

Reviewed-by: Akihiko Odaki <[email protected]>

Regards,
Akihiko Odaki
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.