[PATCH 0/1] hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle

[email protected]
Newsgroups org.kernel.vger.linux-cxl,org.nongnu.qemu-devel
Message-ID <[email protected]>
From: Haotian Jiang <[email protected]>

This issue was found by Tencent Security Yunding Lab during CXL
emulation security research, and reported by Haotian Jiang
<[email protected]>.

cxl_doe_cdat_rsp() in hw/mem/cxl_type3.c:280-282 (Type3) and
hw/pci-bridge/cxl_upstream.c:160-162 (USP) takes
ent = req->entry_handle (uint16_t, fully guest-controlled, 0..0xFFFF)
and directly indexes cdat->entry[ent] without checking
ent < cdat->entry_len. For a default cxl-type3 with one volatile
memory region, entry_len = 7, so any entry_handle >= 7 reads past
the CDATEntry array into host heap.

The OOB-read base/length is then used in
memcpy(read_mbox + offset, base, len) at cxl_type3.c:298-299, leaking
host heap memory to the guest via PCI_EXP_DOE_RD_DATA_MBOX, and
potentially overflowing the 1 MiB read_mbox heap buffer when the OOB
length field is large.

Per QEMU's security policy (docs/system/security.rst), CXL is
classified as non-virtualization use case, so this is reported as a
normal bug rather than through the security process.

A qtest-based PoC (poc.py) is available for reproduction. Under ASAN
it reports SEGV in cxl_doe_cdat_rsp at cxl_type3.c:281.

Haotian Jiang (1):
  hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle

 hw/mem/cxl_type3.c           | 3 +++
 hw/pci-bridge/cxl_upstream.c | 3 +++
 2 files changed, 6 insertions(+)

-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.