On Mon, Sep 07, 2026 at 01:07:46PM +0200, Niklas Cassel wrote: > raw_co_zone_append() checks that the offset it is given is aligned to the > zone size, but not that it names a zone of the device. raw_co_prw() then > derives a zone index from it and reads that entry of the write pointer > array, so an offset past the end of the device reads past the end of the > array. > > bdrv_co_zone_append() does not catch it either: bdrv_check_qiov_request() > bounds the request against BDRV_MAX_LENGTH, which has nothing to do with > the size of this device. A guest cannot reach it, because > check_zoned_request() in virtio-blk rejects an out of range offset first, > but qemu-io and any other caller of blk_co_zone_append() can: > > $ qemu-io --image-opts -n driver=host_device,filename=/dev/nullb0 \ > -c "zap -p 0x100000000000 0x1000" > Segmentation fault > > On a null_blk device with 1000 zones of 256 MiB, that offset yields zone > index 65536 and reads 512 KiB beyond an 8000 byte allocation. > > Reject an offset that lies outside the device. That also bounds the > zone index that raw_co_prw() derives from it, so its write pointer > lookup stays inside the array. > > Fixes: 4751d09adcc3 ("block: introduce zone append write for zoned devices") > Reviewed-by: Damien Le Moal > Signed-off-by: Niklas Cassel > --- > block/file-posix.c | 7 +++++++ > 1 file changed, 7 insertions(+) Reviewed-by: Stefan Hajnoczi