All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Michael S. Tsirkin" <mst@redhat.com>
To: qemu-devel@nongnu.org
Cc: Peter Maydell <peter.maydell@linaro.org>
Subject: Re: [PULL 00/30] pci, vhost, virtio, iommu: bugfixes
Date: Mon, 27 Jul 2026 04:55:51 -0400	[thread overview]
Message-ID: <20260727045453-mutt-send-email-mst@kernel.org> (raw)
In-Reply-To: <cover.1785101237.git.mst@redhat.com>

On Sun, Jul 26, 2026 at 05:29:01PM -0400, Michael S. Tsirkin wrote:
> The following changes since commit cbd42e2b75b23953a9bdb073c8531518b1bd6163:
> 
>   Update version for v11.1.0-rc1 release (2026-07-21 13:18:25 -0400)
> 
> are available in the Git repository at:
> 
>   https://git.kernel.org/pub/scm/virt/kvm/mst/qemu.git tags/for_upstream
> 
> for you to fetch changes up to 13342b9c4104f3bf93c2e52e7de4b383971d7bd6:


moved to f2fe2afd27ddf93b49a16a29e8224d16b9888953 now:
I dropped 
       vmstate: fix type confusion in vmstate_size() for VMSTATE_VBUFFER_UINT64
will go in through the migration tree.

>   backends/rng: cap request size to avoid oversized allocation (2026-07-26 17:26:41 -0400)
> 
> ----------------------------------------------------------------
> pci, vhost, virtio, iommu: bugfixes
> 
> Fixes all over the place, including a bunch of CVE fixes.
> 
> Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
> 
> ----------------------------------------------------------------
> Clément MATHIEU--DRIF (1):
>       intel_iommu: Check address mask before using it in pasid-based iotlb invalidation
> 
> GuoHan Zhao (1):
>       hw/virtio/vdpa-dev: pass set_config buffer to vhost backend
> 
> Haotian Jiang (1):
>       hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle
> 
> Laurent Vivier (4):
>       hw/virtio: reject zero-length packed indirect descriptor table
>       hw/net/virtio-net: Protect from DMA re-entrancy bugs
>       hw/virtio-rng: Fix host use-after-free (CVE-2026-50624)
>       backends/rng: cap request size to avoid oversized allocation
> 
> Manos Pitsidianakis (2):
>       virtio-snd: check rx buffer descriptor size
>       virtio-snd: check for overflow before g_malloc0
> 
> Michael S. Tsirkin (18):
>       virtio: use masked features with set_features_ex
>       virtio-net: fix OOB read in RSC receive path
>       virtio-net: fix short frame OOB read in receive_filter()
>       libvhost-user: protect against OOB writes in vu_set_inflight_fd
>       libvhost-user: protect against OOB vring queue access
>       vhost: do not crash on ring map failure
>       virtio-scsi: fix SCSIRequest leak on a bad request
>       virtio-mmio: fix QUEUE_NUM_MAX
>       virtio: fix queue size validation against allocated maximum
>       virtio: stop migrating num_default, validate vring.num on load
>       virtio: fail early on bad config_len in migration
>       vhost-user: assert nregions within limit
>       virtio-pmem: wait for flush requests on unrealize
>       libvhost-user: validate last_batch_head in vu_check_queue_inflights
>       libvhost-user: fix heap overflow in vu_check_queue_inflights
>       vmstate: fix type confusion in vmstate_size() for VMSTATE_VBUFFER_UINT64
>       libvduse: validate vq size
>       virtio-iommu: fix OOM due to unbounded call_rcu
> 
> Peter Maydell (3):
>       hw/pci-host/q35.c: Always initialize smram-region even if SMM disabled
>       hw/pci-host/q35.c: Factor out creation of SMRAM MRs
>       hw/pci-host/q35.c: Avoid early return in mch_write_config()
> 
>  include/hw/scsi/scsi.h                    |   1 +
>  include/hw/virtio/virtio-bus.h            |   1 +
>  include/hw/virtio/virtio-iommu.h          |   1 +
>  include/hw/virtio/virtio-mmio.h           |   1 +
>  include/hw/virtio/virtio-pmem.h           |   1 +
>  include/migration/vmstate.h               |   5 +-
>  include/system/rng.h                      |  14 ++++
>  backends/rng.c                            |  21 +++++-
>  hw/audio/virtio-snd.c                     |  24 +++++--
>  hw/core/machine.c                         |   1 +
>  hw/i386/intel_iommu.c                     |   9 +++
>  hw/mem/cxl_type3.c                        |   3 +
>  hw/net/virtio-net.c                       |  25 ++++++-
>  hw/pci-bridge/cxl_upstream.c              |   3 +
>  hw/pci-host/q35.c                         | 110 ++++++++++++++++--------------
>  hw/scsi/scsi-bus.c                        |   7 ++
>  hw/scsi/virtio-scsi.c                     |   2 +
>  hw/virtio/vdpa-dev.c                      |   2 +-
>  hw/virtio/vhost-user.c                    |   3 +
>  hw/virtio/vhost.c                         |   5 +-
>  hw/virtio/virtio-iommu.c                  |  29 ++++++++
>  hw/virtio/virtio-mmio.c                   |   7 +-
>  hw/virtio/virtio-pmem.c                   |  17 ++++-
>  hw/virtio/virtio-rng.c                    |   2 +
>  hw/virtio/virtio.c                        |  43 ++++++++----
>  migration/vmstate.c                       |  31 ++++++++-
>  subprojects/libvduse/libvduse.c           |   5 ++
>  subprojects/libvhost-user/libvhost-user.c |  61 ++++++++++++++++-
>  28 files changed, 345 insertions(+), 89 deletions(-)
> 



  parent reply	other threads:[~2026-07-27  8:56 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-26 21:28 [PULL 00/30] pci, vhost, virtio, iommu: bugfixes Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 01/30] virtio: use masked features with set_features_ex Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 02/30] virtio-net: fix OOB read in RSC receive path Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 03/30] virtio-net: fix short frame OOB read in receive_filter() Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 04/30] libvhost-user: protect against OOB writes in vu_set_inflight_fd Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 05/30] libvhost-user: protect against OOB vring queue access Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 06/30] hw/virtio: reject zero-length packed indirect descriptor table Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 07/30] vhost: do not crash on ring map failure Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 08/30] virtio-scsi: fix SCSIRequest leak on a bad request Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 09/30] virtio-mmio: fix QUEUE_NUM_MAX Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 10/30] virtio: fix queue size validation against allocated maximum Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 11/30] virtio: stop migrating num_default, validate vring.num on load Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 12/30] virtio: fail early on bad config_len in migration Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 13/30] vhost-user: assert nregions within limit Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 14/30] virtio-pmem: wait for flush requests on unrealize Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 15/30] libvhost-user: validate last_batch_head in vu_check_queue_inflights Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 16/30] libvhost-user: fix heap overflow " Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 17/30] vmstate: fix type confusion in vmstate_size() for VMSTATE_VBUFFER_UINT64 Michael S. Tsirkin
2026-07-27  0:31   ` Peter Xu
2026-07-27  8:53     ` Michael S. Tsirkin
2026-07-27 12:49       ` Peter Xu
2026-07-27 13:17         ` Michael S. Tsirkin
2026-07-27 14:12           ` Peter Xu
2026-07-27 19:06         ` Michael S. Tsirkin
2026-07-27 20:29           ` Peter Xu
2026-07-27 20:49             ` Michael S. Tsirkin
2026-07-27 22:19               ` Fabiano Rosas
2026-07-27 22:36                 ` Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 18/30] libvduse: validate vq size Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 19/30] virtio-iommu: fix OOM due to unbounded call_rcu Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 20/30] virtio-snd: check rx buffer descriptor size Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 21/30] virtio-snd: check for overflow before g_malloc0 Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 22/30] hw/pci-host/q35.c: Always initialize smram-region even if SMM disabled Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 23/30] hw/pci-host/q35.c: Factor out creation of SMRAM MRs Michael S. Tsirkin
2026-07-26 21:29 ` [PULL 24/30] hw/pci-host/q35.c: Avoid early return in mch_write_config() Michael S. Tsirkin
2026-07-26 21:30 ` [PULL 25/30] hw/virtio/vdpa-dev: pass set_config buffer to vhost backend Michael S. Tsirkin
2026-07-26 21:30 ` [PULL 26/30] hw/cxl: fix OOB access in cxl_doe_cdat_rsp via entry_handle Michael S. Tsirkin
2026-07-26 21:30 ` [PULL 27/30] intel_iommu: Check address mask before using it in pasid-based iotlb invalidation Michael S. Tsirkin
2026-07-26 21:30 ` [PULL 28/30] hw/net/virtio-net: Protect from DMA re-entrancy bugs Michael S. Tsirkin
2026-07-26 21:30 ` [PULL 29/30] hw/virtio-rng: Fix host use-after-free (CVE-2026-50624) Michael S. Tsirkin
2026-07-26 21:30 ` [PULL 30/30] backends/rng: cap request size to avoid oversized allocation Michael S. Tsirkin
2026-07-27  8:55 ` Michael S. Tsirkin [this message]
2026-07-27  9:05   ` [PULL 00/30] pci, vhost, virtio, iommu: bugfixes Marc-André Lureau

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727045453-mutt-send-email-mst@kernel.org \
    --to=mst@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.