On Tue, Oct 06, 2026 at 06:40:54PM +0900, 성병찬 wrote: > Yes, that is a fair summary. > > More precisely, a short successful virtio-scsi response causes the > guest kernel to cache bytes that were not supplied by the device and > expose them through the world-readable VPD sysfs attribute. > > The guest-kernel heap disclosure is reproducible. I agree that its > security classification depends on whether the virtio-scsi > device/backend is considered trusted in the relevant threat model. > > Would validating and propagating the actual virtqueue used length be > worthwhile as a robustness fix? > > Regards, > sungbyeongchan >
I think so but please copy all relevant maintainers. ./scripts/get_maintainer.pl -f drivers/scsi/virtio_scsi.c "Michael S. Tsirkin" <[email protected]> (maintainer:VIRTIO BLOCK AND SCSI DRIVERS) Jason Wang <[email protected]> (maintainer:VIRTIO BLOCK AND SCSI DRIVERS) Paolo Bonzini <[email protected]> (reviewer:VIRTIO BLOCK AND SCSI DRIVERS) Stefan Hajnoczi <[email protected]> (reviewer:VIRTIO BLOCK AND SCSI DRIVERS) "Eugenio Pérez" <[email protected]> (reviewer:VIRTIO BLOCK AND SCSI DRIVERS) "James E.J. Bottomley" <[email protected]> (maintainer:SCSI SUBSYSTEM) "Martin K. Petersen" <[email protected]> (maintainer:SCSI SUBSYSTEM) [email protected] (open list:VIRTIO BLOCK AND SCSI DRIVERS) [email protected] (open list:SCSI SUBSYSTEM) [email protected] (open list) -- MST

