From: Marc-André Lureau <[email protected]>
virtio_gpu_resource_create_blob() stores the guest-controlled blob_size
without checking it against the total size of the iov backing entries.
Since both values are independently guest-controlled, a malicious guest
can set blob_size much larger than the actual iov backing. Subsequent
SET_SCANOUT_BLOB checks bounds against the inflated blob_size, allowing
a pixman surface to be created over the undersized buffer. Any display
refresh then reads past the actual allocation, potentially crashing
QEMU or leaking host memory contents depending on the backing type.
Reject the resource early when the iov backing is smaller than the
declared blob_size.
Fixes: CVE-2026-66021
Fixes: e0933d91b1cd ("virtio-gpu: Add virtio_gpu_resource_create_blob")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3945
Reported-by: "sundayjiang(蒋浩天)" <[email protected]>
Signed-off-by: Marc-André Lureau <[email protected]>
---
hw/display/virtio-gpu.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
index eac039c3c366..cc6dbd116618 100644
--- a/hw/display/virtio-gpu.c
+++ b/hw/display/virtio-gpu.c
@@ -372,6 +372,16 @@ static void virtio_gpu_resource_create_blob(VirtIOGPU *g,
return;
}
+ if (iov_size(res->iov, res->iov_cnt) < res->blob_size) {
+ qemu_log_mask(LOG_GUEST_ERROR,
+ "%s: backing storage smaller than blob size\n",
+ __func__);
+ cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER;
+ virtio_gpu_cleanup_mapping(g, res);
+ g_free(res);
+ return;
+ }
+
virtio_gpu_init_udmabuf(res);
QTAILQ_INSERT_HEAD(&g->reslist, res, next);
}
--
2.55.0