All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] vhost: Reject oversized inflight migration buffers
@ 2026-07-27 12:45 김승중
  2026-07-27 12:48 ` Michael S. Tsirkin
  0 siblings, 1 reply; 4+ messages in thread
From: 김승중 @ 2026-07-27 12:45 UTC (permalink / raw)
  To: qemu-devel
  Cc: Michael S. Tsirkin, Stefano Garzarella, Daniel P. Berrangé,
	Mauro Matteo Cascella

The inflight buffer size is migrated as a uint64_t, but vmstate_size()
reads VMS_VBUFFER sizes as int32_t. Values above INT32_MAX therefore
become negative and are converted to a very large size_t while loading
the buffer, allowing writes beyond the smaller memfd-backed mapping.

Reject sizes that cannot be represented by vmstate_size() before
allocating the destination buffer.

Fixes: CVE-2026-6426
Reported-by: Seungjung Kim <seungjung0711@gmail.com>
Signed-off-by: Seungjung Kim <seungjung0711@gmail.com>

diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c
index af41841b52..82eb9407ae 100644
--- a/hw/virtio/vhost.c
+++ b/hw/virtio/vhost.c
@@ -2022,11 +2022,18 @@ void vhost_get_features_ex(struct vhost_dev *hdev,
 static bool vhost_inflight_buffer_pre_load(void *opaque, Error **errp)
 {
     struct vhost_inflight *inflight = opaque;
-
     int fd = -1;
-    void *addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
-                                  F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
-                                  &fd, errp);
+    void *addr;
+
+    if (inflight->size > INT32_MAX) {
+        error_setg(errp, "inflight buffer size %" PRIu64
+                   " exceeds maximum %d", inflight->size, INT32_MAX);
+        return false;
+    }
+
+    addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
+                            F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
+                            &fd, errp);
     if (!addr) {
         return false;
     }
-- 
2.50.1 (Apple Git-155)


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH] vhost: Reject oversized inflight migration buffers
  2026-07-27 12:45 [PATCH] vhost: Reject oversized inflight migration buffers 김승중
@ 2026-07-27 12:48 ` Michael S. Tsirkin
  2026-07-27 13:02   ` 김승중
  0 siblings, 1 reply; 4+ messages in thread
From: Michael S. Tsirkin @ 2026-07-27 12:48 UTC (permalink / raw)
  To: 김승중
  Cc: qemu-devel, Stefano Garzarella, Daniel P. Berrangé,
	Mauro Matteo Cascella

On Mon, Jul 27, 2026 at 05:45:47AM -0700, 김승중 wrote:
> The inflight buffer size is migrated as a uint64_t, but vmstate_size()
> reads VMS_VBUFFER sizes as int32_t. Values above INT32_MAX therefore
> become negative and are converted to a very large size_t while loading
> the buffer, allowing writes beyond the smaller memfd-backed mapping.
> 
> Reject sizes that cannot be represented by vmstate_size() before
> allocating the destination buffer.
> 
> Fixes: CVE-2026-6426

This CVE really shouldn't be there.

> Reported-by: Seungjung Kim <seungjung0711@gmail.com>
> Signed-off-by: Seungjung Kim <seungjung0711@gmail.com>

This doen't fix it properly, it only fixes values 2g to 4g, but above 4g
is still wrong.

A better fix here:
https://lore.kernel.org/all/9e2d0b03a60642236e6df8edde7b3562f5f9849f.1785101237.git.mst@redhat.com/

> 
> diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c
> index af41841b52..82eb9407ae 100644
> --- a/hw/virtio/vhost.c
> +++ b/hw/virtio/vhost.c
> @@ -2022,11 +2022,18 @@ void vhost_get_features_ex(struct vhost_dev *hdev,
>  static bool vhost_inflight_buffer_pre_load(void *opaque, Error **errp)
>  {
>      struct vhost_inflight *inflight = opaque;
> -
>      int fd = -1;

pls don't make unrelated changes like this.

> -    void *addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> -                                  F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> -                                  &fd, errp);
> +    void *addr;
> +
> +    if (inflight->size > INT32_MAX) {
> +        error_setg(errp, "inflight buffer size %" PRIu64
> +                   " exceeds maximum %d", inflight->size, INT32_MAX);
> +        return false;
> +    }
> +
> +    addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> +                            F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> +                            &fd, errp);
>      if (!addr) {
>          return false;
>      }
> -- 
> 2.50.1 (Apple Git-155)



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] vhost: Reject oversized inflight migration buffers
  2026-07-27 12:48 ` Michael S. Tsirkin
@ 2026-07-27 13:02   ` 김승중
  2026-07-27 13:16     ` Michael S. Tsirkin
  0 siblings, 1 reply; 4+ messages in thread
From: 김승중 @ 2026-07-27 13:02 UTC (permalink / raw)
  To: Michael S. Tsirkin
  Cc: qemu-devel, Stefano Garzarella, Daniel P. Berrangé,
	Mauro Matteo Cascella

Thanks Michael. Understood.

The pre_load check was intended as an immediate mitigation, but I see
that it does not address the VMSTATE_VBUFFER_UINT64 type confusion in
the common load and save paths. I will defer to the generic vmstate
fix and will not resend this patch.

I included "Fixes: CVE-2026-6426" because Mauro requested that exact
trailer when the CVE was assigned. I understand that under the current
QEMU security policy, vhost-user-backend-originated issues are treated
as hardening bugs rather than security flaws.

Could you please retain the following credit on the final fix?

Reported-by: Seungjung Kim <seungjung0711@gmail.com>

Sorry about the unrelated whitespace change.

Thanks,
Seungjung


On Mon, 27 Jul 2026 08:48:56 -0400, "Michael S. Tsirkin" <mst@redhat.com> wrote:
> On Mon, Jul 27, 2026 at 05:45:47AM -0700, 김승중 wrote:
> > The inflight buffer size is migrated as a uint64_t, but vmstate_size()
> > reads VMS_VBUFFER sizes as int32_t. Values above INT32_MAX therefore
> > become negative and are converted to a very large size_t while loading
> > the buffer, allowing writes beyond the smaller memfd-backed mapping.
> >
> > Reject sizes that cannot be represented by vmstate_size() before
> > allocating the destination buffer.
> >
> > Fixes: CVE-2026-6426
>
> This CVE really shouldn't be there.
>
> > Reported-by: Seungjung Kim <seungjung0711@gmail.com>
> > Signed-off-by: Seungjung Kim <seungjung0711@gmail.com>
>
> This doen't fix it properly, it only fixes values 2g to 4g, but above 4g
> is still wrong.
>
> A better fix here:
> https://lore.kernel.org/all/9e2d0b03a60642236e6df8edde7b3562f5f9849f.1785101237.git.mst@redhat.com/
>
> >
> > diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c
> > index af41841b52..82eb9407ae 100644
> > --- a/hw/virtio/vhost.c
> > +++ b/hw/virtio/vhost.c
> > @@ -2022,11 +2022,18 @@ void vhost_get_features_ex(struct vhost_dev *hdev,
> > static bool vhost_inflight_buffer_pre_load(void *opaque, Error **errp)
> > {
> > struct vhost_inflight *inflight = opaque;
> > -
> > int fd = -1;
>
> pls don't make unrelated changes like this.
>
> > - void *addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> > - F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> > - &fd, errp);
> > + void *addr;
> > +
> > + if (inflight->size > INT32_MAX) {
> > + error_setg(errp, "inflight buffer size %" PRIu64
> > + " exceeds maximum %d", inflight->size, INT32_MAX);
> > + return false;
> > + }
> > +
> > + addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> > + F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> > + &fd, errp);
> > if (!addr) {
> > return false;
> > }
> > --
> > 2.50.1 (Apple Git-155)


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] vhost: Reject oversized inflight migration buffers
  2026-07-27 13:02   ` 김승중
@ 2026-07-27 13:16     ` Michael S. Tsirkin
  0 siblings, 0 replies; 4+ messages in thread
From: Michael S. Tsirkin @ 2026-07-27 13:16 UTC (permalink / raw)
  To: 김승중
  Cc: qemu-devel, Stefano Garzarella, Daniel P. Berrangé,
	Mauro Matteo Cascella

On Mon, Jul 27, 2026 at 06:02:26AM -0700, 김승중 wrote:
> Thanks Michael. Understood.
> 
> The pre_load check was intended as an immediate mitigation, but I see
> that it does not address the VMSTATE_VBUFFER_UINT64 type confusion in
> the common load and save paths. I will defer to the generic vmstate
> fix and will not resend this patch.
> 
> I included "Fixes: CVE-2026-6426" because Mauro requested that exact
> trailer when the CVE was assigned. I understand that under the current
> QEMU security policy, vhost-user-backend-originated issues are treated
> as hardening bugs rather than security flaws.
> 
> Could you please retain the following credit on the final fix?
> 
> Reported-by: Seungjung Kim <seungjung0711@gmail.com>

Indeed, my apologies for missing that.

> Sorry about the unrelated whitespace change.
> 
> Thanks,
> Seungjung
> 
> 
> On Mon, 27 Jul 2026 08:48:56 -0400, "Michael S. Tsirkin" <mst@redhat.com> wrote:
> > On Mon, Jul 27, 2026 at 05:45:47AM -0700, 김승중 wrote:
> > > The inflight buffer size is migrated as a uint64_t, but vmstate_size()
> > > reads VMS_VBUFFER sizes as int32_t. Values above INT32_MAX therefore
> > > become negative and are converted to a very large size_t while loading
> > > the buffer, allowing writes beyond the smaller memfd-backed mapping.
> > >
> > > Reject sizes that cannot be represented by vmstate_size() before
> > > allocating the destination buffer.
> > >
> > > Fixes: CVE-2026-6426
> >
> > This CVE really shouldn't be there.
> >
> > > Reported-by: Seungjung Kim <seungjung0711@gmail.com>
> > > Signed-off-by: Seungjung Kim <seungjung0711@gmail.com>
> >
> > This doen't fix it properly, it only fixes values 2g to 4g, but above 4g
> > is still wrong.
> >
> > A better fix here:
> > https://lore.kernel.org/all/9e2d0b03a60642236e6df8edde7b3562f5f9849f.1785101237.git.mst@redhat.com/
> >
> > >
> > > diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c
> > > index af41841b52..82eb9407ae 100644
> > > --- a/hw/virtio/vhost.c
> > > +++ b/hw/virtio/vhost.c
> > > @@ -2022,11 +2022,18 @@ void vhost_get_features_ex(struct vhost_dev *hdev,
> > > static bool vhost_inflight_buffer_pre_load(void *opaque, Error **errp)
> > > {
> > > struct vhost_inflight *inflight = opaque;
> > > -
> > > int fd = -1;
> >
> > pls don't make unrelated changes like this.
> >
> > > - void *addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> > > - F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> > > - &fd, errp);
> > > + void *addr;
> > > +
> > > + if (inflight->size > INT32_MAX) {
> > > + error_setg(errp, "inflight buffer size %" PRIu64
> > > + " exceeds maximum %d", inflight->size, INT32_MAX);
> > > + return false;
> > > + }
> > > +
> > > + addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> > > + F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> > > + &fd, errp);
> > > if (!addr) {
> > > return false;
> > > }
> > > --
> > > 2.50.1 (Apple Git-155)



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-07-27 13:18 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 12:45 [PATCH] vhost: Reject oversized inflight migration buffers 김승중
2026-07-27 12:48 ` Michael S. Tsirkin
2026-07-27 13:02   ` 김승중
2026-07-27 13:16     ` Michael S. Tsirkin

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.