[Stable-11.0.4 039/120] virtio-gpu: fix NULL deref in rutabaga set_scanout
Michael Tokarev <[email protected]>
| Newsgroups | gmane.comp.emulators.qemu,gmane.comp.emulators.qemu.stable |
|---|---|
| Message-ID | <[email protected]> |
From: Haotian Jiang <[email protected]> rutabaga_cmd_set_scanout() checks scanout_id < VIRTIO_GPU_MAX_SCANOUTS (16), but does not check scanout_id < conf.max_outputs like the base class (virtio-gpu.c) and virgl backend (virtio-gpu-virgl.c) do. With the default max_outputs=1, virtio_gpu_base_device_realize only initializes scanout[0].con. A guest submitting SET_SCANOUT with scanout_id >= 1 takes the con=NULL path, and qemu_console_set_surface(NULL, NULL) dereferences con->ds, crashing QEMU. Replace VIRTIO_GPU_MAX_SCANOUTS with vb->conf.max_outputs in the CHECK, since realization already ensures max_outputs <= VIRTIO_GPU_MAX_SCANOUTS. Fixes: 1dcc6adbc168 ("gfxstream + rutabaga: add initial support for gfxstream") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3897 Cc: [email protected] Message-ID: <[email protected]> Reviewed-by: Dmitry Osipenko <[email protected]> Reviewed-by: Marc-André Lureau <[email protected]> Signed-off-by: Haotian Jiang <[email protected]> (cherry picked from commit 8ac0a1c7b98e11693db8fc6b390cc892b6e3e6c8) Signed-off-by: Michael Tokarev <[email protected]> diff --git a/hw/display/virtio-gpu-rutabaga.c b/hw/display/virtio-gpu-rutabaga.c index e5e85fde583..17ccfa51170 100644 --- a/hw/display/virtio-gpu-rutabaga.c +++ b/hw/display/virtio-gpu-rutabaga.c @@ -302,7 +302,7 @@ rutabaga_cmd_set_scanout(VirtIOGPU *g, struct virtio_gpu_ctrl_command *cmd) trace_virtio_gpu_cmd_set_scanout(ss.scanout_id, ss.resource_id, ss.r.width, ss.r.height, ss.r.x, ss.r.y); - CHECK(ss.scanout_id < VIRTIO_GPU_MAX_SCANOUTS, cmd); + CHECK(ss.scanout_id < vb->conf.max_outputs, cmd); scanout = &vb->scanout[ss.scanout_id]; if (ss.resource_id == 0) { -- 2.47.3