A guest might send a too short SCCB with SCLP_EVENT_CTRL_PGM_ID. QEMU
would fill its data structures with garbage data. Check for the precise
length of the CBI data structure and reject otherwise.

Fixes: f345978f24be ("hw/s390x: add Control-Program Identification to QOM")
Cc: [email protected]
Signed-off-by: Christian Borntraeger <[email protected]>
Reviewed-by: Matthew Rosato <[email protected]>
Reviewed-by: Janosch Frank <[email protected]>
---
 hw/s390x/sclpcpi.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/hw/s390x/sclpcpi.c b/hw/s390x/sclpcpi.c
index 68fc1b809b..ec4bdf2350 100644
--- a/hw/s390x/sclpcpi.c
+++ b/hw/s390x/sclpcpi.c
@@ -97,6 +97,11 @@ static int write_event_data(SCLPEvent *event, 
EventBufferHeader *evt_buf_hdr)
                                              ebh);
     SCLPEventCPI *e = SCLP_EVENT_CPI(event);
 
+    /* Caller checks sccb length, buffer header checking is our duty */
+    if (be16_to_cpu(evt_buf_hdr->length) != sizeof(ControlProgramIdMsg)) {
+        return SCLP_RC_INCONSISTENT_LENGTHS;
+    }
+
     ascii_put(e->system_type, (char *)cpim->data.system_type,
               sizeof(cpim->data.system_type));
     ascii_put(e->system_name, (char *)cpim->data.system_name,
-- 
2.53.0


Reply via email to