Yes, that is a fair summary.

More precisely, a short successful virtio-scsi response causes the
guest kernel to cache bytes that were not supplied by the device and
expose them through the world-readable VPD sysfs attribute.

The guest-kernel heap disclosure is reproducible. I agree that its
security classification depends on whether the virtio-scsi
device/backend is considered trusted in the relevant threat model.

Would validating and propagating the actual virtqueue used length be
worthwhile as a robustness fix?

Regards,
sungbyeongchan

Reply via email to