vu_check_queue_inflights counts inflight descriptors using inflight == 1
but copies entries using inflight != 0. If the inflight field contains
an unexpected non-0/1 value, the function copies more entries than it
allocates and overflows the heap buffer.
Stop the copy pass once resubmit_num reaches the counted inuse value.
Note: the value is not guest-accessible so not a security vulnerability.
Fixes: CVE-2026-63110
Fixes: 5f9ff1eff3 ("libvhost-user: Support tracking inflight I/O in shared
memory")
Cc: Xie Yongji <[email protected]>
Cc: Stefano Garzarella <[email protected]>
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3974
Signed-off-by: Michael S. Tsirkin <[email protected]>
---
subprojects/libvhost-user/libvhost-user.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/subprojects/libvhost-user/libvhost-user.c
b/subprojects/libvhost-user/libvhost-user.c
index c1c13dbc90..a74d814bb4 100644
--- a/subprojects/libvhost-user/libvhost-user.c
+++ b/subprojects/libvhost-user/libvhost-user.c
@@ -1408,6 +1408,13 @@ vu_check_queue_inflights(VuDev *dev, VuVirtq *vq)
for (i = 0; i < vq->inflight->desc_num; i++) {
if (vq->inflight->desc[i].inflight) {
+ /*
+ * We earlier counted exactly vq->inuse in flight -
+ * what is going on?
+ */
+ if (vq->resubmit_num >= vq->inuse) {
+ return -1;
+ }
vq->resubmit_list[vq->resubmit_num].index = i;
vq->resubmit_list[vq->resubmit_num].counter =
vq->inflight->desc[i].counter;
--
MST