All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Marc-André Lureau" <marcandre.lureau@redhat.com>
To: qemu-devel@nongnu.org
Cc: "Marc-André Lureau" <marcandre.lureau@redhat.com>,
	"Michael S. Tsirkin" <mst@redhat.com>,
	"Stefano Garzarella" <sgarzare@redhat.com>
Subject: [GIT PULL 11/14] vhost-user-gpu: validate command buffer size in submit_3d
Date: Sun, 13 Sep 2026 14:41:29 +0400	[thread overview]
Message-ID: <20260913-ui-v1-11-7a8d89d0423a@redhat.com> (raw)
In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com>

virgl_cmd_submit_3d() passes the guest-controlled cs.size directly to
g_malloc() without any bounds check. A malicious guest can set this
field to an arbitrarily large value (up to 4GB), causing an OOM abort
that crashes the vhost-user-gpu daemon.

Validate cs.size against the actual descriptor payload size before
allocating, rejecting values that exceed what the virtqueue entry
can carry.

Fixes: d52c454aadc ("contrib: add vhost-user-gpu")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3776
Reported-by: admin@fluentlogic.org
Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260713125431.107278-1-marcandre.lureau@redhat.com>
Message-ID: <67f10fb88d3c75da3ba7fa5a37f7d6bcfcf3ce9e.1789071042.git.mst@redhat.com>
---
 contrib/vhost-user-gpu/virgl.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/contrib/vhost-user-gpu/virgl.c b/contrib/vhost-user-gpu/virgl.c
index 5a5f9f14c80c..0ef4b9d8c903 100644
--- a/contrib/vhost-user-gpu/virgl.c
+++ b/contrib/vhost-user-gpu/virgl.c
@@ -209,20 +209,24 @@ virgl_cmd_submit_3d(VuGpu *g,
                     struct virtio_gpu_ctrl_command *cmd)
 {
     struct virtio_gpu_cmd_submit cs;
+    size_t iov_len;
     void *buf;
     size_t s;
 
     VUGPU_FILL_CMD(cs);
 
-    if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) {
-        g_critical("%s: command buffer too large (%u)",
-                   __func__, cs.size);
+    iov_len = iov_size(cmd->elem.out_sg, cmd->elem.out_num);
+    if (cs.size == 0 || iov_len < sizeof(cs) ||
+        cs.size > iov_len - sizeof(cs) ||
+        cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) {
+        g_critical("%s: size out of range (%u/%zu)",
+                   __func__, cs.size, iov_len);
         cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER;
         return;
     }
 
     buf = g_try_malloc(cs.size);
-    if (!buf && cs.size) {
+    if (!buf) {
         cmd->error = VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY;
         return;
     }

-- 
2.55.0.543.g5ebe2ebe4ea8



  parent reply	other threads:[~2026-09-13 10:44 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13 10:41 [GIT PULL 00/14] UI/display queue Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 01/14] ui/dbus: fix cursor race, copy cursor data Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 02/14] hw/display/qxl: hold ssd.lock while replacing ssd.cursor Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 03/14] ui/cursor: make the cursor refcount atomic Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 04/14] docs/sphinx/dbus: register build dependency Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 05/14] ui/dbus: add org.qemu.Display1.UIInfo interface Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 06/14] hw/display/qxl: factor out qxl_guest_phys2virt() Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 07/14] hw/display/qxl: validate replayed commands in qxl_post_load Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 08/14] hw/display/qxl: trace skipped stale loadvm commands Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 09/14] ui/gtk: Remove glFlush() after eglSwapBuffers() Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 10/14] ui/gtk: Work around the gtk-menu-bar-accel leak Marc-André Lureau
2026-09-13 10:41 ` Marc-André Lureau [this message]
2026-09-13 10:41 ` [GIT PULL 12/14] virtio-gpu-virgl: guard new_blob with VIRGL_VERSION_MAJORS>=1 Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 13/14] ui/gtk: Handle empty notebook state in menu handlers Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 14/14] ui/gtk: Clean up GL resources on tab detach, re-attach, and VC free Marc-André Lureau

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260913-ui-v1-11-7a8d89d0423a@redhat.com \
    --to=marcandre.lureau@redhat.com \
    --cc=mst@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=sgarzare@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.