On 15/7/26 09:27, [email protected] wrote:
From: Marc-André Lureau <[email protected]>The qxl_phys2virt() call for guest_monitors_config only validates sizeof(QXLMonitorsConfig), which covers the fixed header (count and max_allowed) since commit 8efec0ef8bbc ("hw/display/qxl: Pass requested buffer size to qxl_phys2virt()"), but not the flexible array member heads[]. When count == 1, heads[0] is accessed without its memory being validated, allowing a guest to cause an out-of-bounds read. Include sizeof(QXLHead) in the size passed to qxl_phys2virt() so that the first head entry is validated within the guest memory slot, preventing guest-visible memory reading. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4027 Reported-by: Tristan @TristanInSec Signed-off-by: Marc-Andre Lureau <[email protected]> --- hw/display/qxl.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
Patch queued, thanks.
