From: "Denis V. Lunev" <den@openvz.org>
To: qemu-block@nongnu.org
Cc: qemu-devel@nongnu.org, "Denis V. Lunev" <den@openvz.org>,
Stefan Hajnoczi <stefanha@redhat.com>,
Thomas Huth <thuth@redhat.com>
Subject: [PULL 03/29] parallels: bound the bitmap L1 table against the bitmap size
Date: Fri, 11 Sep 2026 01:41:56 +0200 [thread overview]
Message-ID: <20260910234222.3039975-4-den@openvz.org> (raw)
In-Reply-To: <20260910234222.3039975-1-den@openvz.org>
From: Denis V. Lunev <den@openvz.org>
parallels_load_bitmap_data() derives the number of bytes to
deserialize from "bm_size - offset" without checking that the offset
is still inside the bitmap, and an offset past the end makes that
subtraction underflow.
The overflow which used to produce such an offset is fixed by
"dirty-bitmap: fix integer overflow in serialization coverage", but
both the cluster size and the L1 contents come from the image, so
refuse the table explicitly. The check cannot reject a valid table:
l1_size is DIV_ROUND_UP(bm_size, limit), so the largest offset the
loop reaches is (l1_size - 1) * limit, always below bm_size.
Fixes: baefd977002e ("parallels: support bitmap extension for read-only mode")
Cc: Stefan Hajnoczi <stefanha@redhat.com>
Cc: Thomas Huth <thuth@redhat.com>
Signed-off-by: Denis V. Lunev <den@openvz.org>
---
block/parallels-ext.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/block/parallels-ext.c b/block/parallels-ext.c
index 830ac78a11..63fe4d5b1e 100644
--- a/block/parallels-ext.c
+++ b/block/parallels-ext.c
@@ -76,8 +76,17 @@ parallels_load_bitmap_data(BlockDriverState *bs, const uint64_t *l1_table,
buf = qemu_blockalign(bs, s->cluster_size);
limit = bdrv_dirty_bitmap_serialization_coverage(s->cluster_size, bitmap);
for (i = 0, offset = 0; i < l1_size; ++i, offset += limit) {
- uint64_t count = MIN(bm_size - offset, limit);
- uint64_t entry = l1_table[i];
+ uint64_t count, entry;
+
+ if (offset >= bm_size) {
+ error_setg(errp, "Bitmap L1 table covers more than the bitmap "
+ "size %" PRIu64, bm_size);
+ ret = -EINVAL;
+ goto finish;
+ }
+
+ count = MIN(bm_size - offset, limit);
+ entry = l1_table[i];
if (entry == 0) {
/* No need to deserialize zeros because @bitmap is cleared. */
--
2.53.0
next prev parent reply other threads:[~2026-09-11 1:12 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 23:41 [PULL 00/29] parallels: persistent dirty bitmaps and Format Extension hardening Denis V. Lunev
2026-09-10 23:41 ` [PULL 01/29] parallels: fix out-of-bounds read in format extension parsing Denis V. Lunev
2026-09-10 23:41 ` [PULL 02/29] parallels: validate dirty bitmap granularity Denis V. Lunev
2026-09-10 23:41 ` Denis V. Lunev [this message]
2026-09-10 23:41 ` [PULL 04/29] parallels: reject a Format Extension outside the image file Denis V. Lunev
2026-09-10 23:41 ` [PULL 05/29] parallels: allocate the Format Extension cluster gracefully Denis V. Lunev
2026-09-10 23:41 ` [PULL 06/29] parallels: fix GSList leak on the format extension success path Denis V. Lunev
2026-09-10 23:42 ` [PULL 07/29] iotests: cover the Parallels format extension parser Denis V. Lunev
2026-09-10 23:42 ` [PULL 08/29] parallels: Set s->used_bmap to NULL in parallels_free_used_bitmap() Denis V. Lunev
2026-09-10 23:42 ` [PULL 09/29] parallels: split inactivation out and add the activation counterpart Denis V. Lunev
2026-09-10 23:42 ` [PULL 10/29] iotests: cover inactivating a read-only node Denis V. Lunev
2026-09-10 23:42 ` [PULL 11/29] parallels: Make mark_used() a global function Denis V. Lunev
2026-09-10 23:42 ` [PULL 12/29] parallels: Limit search in parallels_mark_used to the last marked cluster Denis V. Lunev
2026-09-10 23:42 ` [PULL 13/29] parallels: Move host clusters allocation to a separate function Denis V. Lunev
2026-09-10 23:42 ` [PULL 14/29] parallels: do not let the check die on what it is meant to report Denis V. Lunev
2026-09-10 23:42 ` [PULL 15/29] parallels: Create used bitmap even if checks needed Denis V. Lunev
2026-09-10 23:42 ` [PULL 16/29] parallels: Drop unused clusters at the end of the image Denis V. Lunev
2026-09-10 23:42 ` [PULL 17/29] parallels: Remove unnecessary data_end field Denis V. Lunev
2026-09-10 23:42 ` [PULL 18/29] parallels: Add dirty bitmaps saving Denis V. Lunev
2026-09-10 23:42 ` [PULL 19/29] parallels: Let image extensions work in RW mode Denis V. Lunev
2026-09-10 23:42 ` [PULL 20/29] parallels: Handle L1 entries equal to one Denis V. Lunev
2026-09-10 23:42 ` [PULL 21/29] iotests: cover the Format Extension against the leak check Denis V. Lunev
2026-09-10 23:42 ` [PULL 22/29] iotests: run the persistent dirty bitmap test on parallels Denis V. Lunev
2026-09-10 23:42 ` [PULL 23/29] parallels: reject a bitmap L1 entry outside the data area Denis V. Lunev
2026-09-10 23:42 ` [PULL 24/29] parallels: do not trust the bitmaps of an image which was not closed Denis V. Lunev
2026-09-10 23:42 ` [PULL 25/29] parallels: implement removing a stored dirty bitmap Denis V. Lunev
2026-09-10 23:42 ` [PULL 26/29] iotests: rename parallels-read-bitmap to parallels-bitmap Denis V. Lunev
2026-09-10 23:42 ` [PULL 27/29] iotests: cover a broken Format Extension and a combined repair Denis V. Lunev
2026-09-10 23:42 ` [PULL 28/29] tests: Turned on 256, 299, 304 and block-status-cache for parallels format Denis V. Lunev
2026-09-10 23:42 ` [PULL 29/29] tests: Add parallels format support to image-fleecing Denis V. Lunev
2026-09-11 10:51 ` [PULL 00/29] parallels: persistent dirty bitmaps and Format Extension hardening Richard Henderson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910234222.3039975-4-den@openvz.org \
--to=den@openvz.org \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=stefanha@redhat.com \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.