On Mon, 6 Jul 2026 at 21:43, Philippe Mathieu-Daudé <[email protected]> wrote: > > On 6/7/26 20:20, Peter Maydell wrote: > > In usb_wacom_handle_data() we allocate a buffer with a size > > determined by the transfer size requested by the guest. We then fill > > it in by calling either usb_mouse_poll() or usb_wacom_poll(), both of > > which functions take a length and return an actual length, which we > > pass to usb_packet_copy(). However, usb_mouse_poll() doesn't check > > the buffer size as it fills in the buffer, so if the guest passes an > > overly short transfer size then it will write off the end of the > > allocated buffer. > > > > Check the length is at least big enough for the minimum 3 byte > > packet and return nothing if it is not, as usb_wacom_poll() does. > > > > Cc: [email protected] > > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3672 > > Signed-off-by: Peter Maydell <[email protected]> > > --- > > hw/usb/dev-wacom.c | 4 ++++ > > 1 file changed, 4 insertions(+) > > > > diff --git a/hw/usb/dev-wacom.c b/hw/usb/dev-wacom.c > > index c69e247f7b..895edcc17e 100644 > > --- a/hw/usb/dev-wacom.c > > +++ b/hw/usb/dev-wacom.c > > @@ -285,6 +285,10 @@ static int usb_mouse_poll(USBWacomState *s, uint8_t > > *buf, int len) > > b |= 0x04; > > } > > > > + if (len < 3) { > > Maybe log GUEST_ERROR? Anyway: > Reviewed-by: Philippe Mathieu-Daudé <[email protected]>
Thanks; I'll take this via target-arm.next as I'm putting together a pullreq anyway. -- PMM
