Am 13.07.2026 um 05:17 hat malike geschrieben:
> The total_sectors is computed as n_blocks * sectors_per_block where
> both operands are uint32_t. The multiplication is performed in 32-bit
> arithmetic and can overflow when the product exceeds UINT32_MAX,
> producing a value much smaller than the true image size. The result
> is assigned to int64_t total_sectors but the 32-bit multiplication
> has already wrapped around, and the zero-extension to 64-bit does
> not recover the correct value.
> 
> This causes the block layer to reject valid I/O requests (DoS) when
> the reported total_sectors is smaller than the actual image.
> 
> Use 64-bit arithmetic by casting one operand to uint64_t so the
> multiplication is performed in 64-bit precision.
> 
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3972
> Signed-off-by: Ma Like <[email protected]>

Thanks, applied to the block branch.

Kevin


Reply via email to