On Tue, Oct 06, 2026 at 06:40:54PM +0900, 성병찬 wrote:
> Yes, that is a fair summary.
> 
> More precisely, a short successful virtio-scsi response causes the
> guest kernel to cache bytes that were not supplied by the device and
> expose them through the world-readable VPD sysfs attribute.
> 
> The guest-kernel heap disclosure is reproducible. I agree that its
> security classification depends on whether the virtio-scsi
> device/backend is considered trusted in the relevant threat model.
> 
> Would validating and propagating the actual virtqueue used length be
> worthwhile as a robustness fix?
> 
> Regards,
> sungbyeongchan
> 

I think so but please copy all relevant maintainers.

 ./scripts/get_maintainer.pl -f drivers/scsi/virtio_scsi.c
"Michael S. Tsirkin" <[email protected]> (maintainer:VIRTIO BLOCK AND SCSI 
DRIVERS)
Jason Wang <[email protected]> (maintainer:VIRTIO BLOCK AND SCSI DRIVERS)
Paolo Bonzini <[email protected]> (reviewer:VIRTIO BLOCK AND SCSI DRIVERS)
Stefan Hajnoczi <[email protected]> (reviewer:VIRTIO BLOCK AND SCSI DRIVERS)
"Eugenio Pérez" <[email protected]> (reviewer:VIRTIO BLOCK AND SCSI DRIVERS)
"James E.J. Bottomley" <[email protected]> (maintainer:SCSI 
SUBSYSTEM)
"Martin K. Petersen" <[email protected]> (maintainer:SCSI SUBSYSTEM)
[email protected] (open list:VIRTIO BLOCK AND SCSI DRIVERS)
[email protected] (open list:SCSI SUBSYSTEM)
[email protected] (open list)


-- 
MST


Reply via email to