On Fri, Jul 17, 2026 at 11:07 AM Akihiko Odaki <[email protected]> wrote: > > pixman_image_create_bits() returns NULL for allocation failures and > unaligned strides, which may be supplied by the guest with > VIRTIO_GPU_CMD_SET_SCANOUT_BLOB, and virtio_gpu_do_set_scanout() > subsequently dereferences it. > > Fixes: fa06e5cb7b10 ("virtio-gpu: fix scanout rectangles") > Signed-off-by: Akihiko Odaki <[email protected]>
Reviewed-by: Marc-André Lureau <[email protected]> > --- > hw/display/virtio-gpu.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c > index 88526051a992..edbb02ee0516 100644 > --- a/hw/display/virtio-gpu.c > +++ b/hw/display/virtio-gpu.c > @@ -674,6 +674,10 @@ static bool virtio_gpu_do_set_scanout(VirtIOGPU *g, > void *ptr = data + fb->offset; > rect = pixman_image_create_bits(fb->format, r->width, r->height, > ptr, fb->stride); > + if (!rect) { > + *error = VIRTIO_GPU_RESP_ERR_UNSPEC; > + return false; > + } > > if (res->image) { > pixman_image_ref(res->image); > > --- > base-commit: 499039798cdad7d86b787fec0eaf1da4151c0f05 > change-id: 20260716-pixman-58020972475d > > Best regards, > -- > Akihiko Odaki <[email protected]> > > -- Marc-André Lureau
