Re: [PATCH] hw/virtio/virtio-iommu: Reject inverted MAP range
"Michael S. Tsirkin" <[email protected]> Mon, 3 Aug 2026 06:25:19 -0400
| Newsgroups | org.nongnu.qemu-devel |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Aug 03, 2026 at 05:43:02PM +0800, Bin Guo wrote: > virtio_iommu_map() did not check that virt_end >= virt_start. An > inverted range corrupts the GTree comparator contract (interval_cmp > returns non-zero for a key compared with itself), causing an infinite > loop in virtio_iommu_unmap() while holding s->mutex. > > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4104 > Cc: [email protected] > Signed-off-by: Bin Guo <[email protected]> Same as [email protected] ? > --- > hw/virtio/virtio-iommu.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/hw/virtio/virtio-iommu.c b/hw/virtio/virtio-iommu.c > index 533bd5073f..cc863e90d2 100644 > --- a/hw/virtio/virtio-iommu.c > +++ b/hw/virtio/virtio-iommu.c > @@ -807,6 +807,10 @@ static int virtio_iommu_map(VirtIOIOMMU *s, > return VIRTIO_IOMMU_S_INVAL; > } > > + if (virt_end < virt_start) { > + return VIRTIO_IOMMU_S_INVAL; > + } > + > domain = g_tree_lookup(s->domains, GUINT_TO_POINTER(domain_id)); > if (!domain) { > return VIRTIO_IOMMU_S_NOENT; > -- > 2.50.1 (Apple Git-155)