Hi

On Sun, Jul 26, 2026 at 8:54 PM Michael Tokarev <[email protected]> wrote:
>
> On 7/6/26 15:53, Marc-André Lureau wrote:
> > vnc_refresh_lossy_rect() always marks a full VNC_STAT_RECT (64) rows
> > as dirty when refreshing a lossy tile. When the display height is not
> > a multiple of VNC_STAT_RECT (e.g. VNC_MAX_HEIGHT = 2160), the bottom
> > tile is partial -- the last tile at y=2112 has only 48 valid rows.
> > The unclamped loop writes to vs->dirty[2160..2175], past the end of
> > the VNC_MAX_HEIGHT-sized array.
> >
> > Clamp the row count to the actual surface height so partial bottom
> > tiles only mark valid dirty bitmap entries.
> >
> > Fixes: CVE-2026-48002
> > Fixes: 7d964c9d2fc6 ("vnc: refresh lossy rect after a given timeout")
> > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3950
> > Reported-by: huntr bubble
> > Signed-off-by: Marc-Andre Lureau <[email protected]>
>
> This patch has already been merged to the qemu master branch
> (as commit 3543c2b855c), but it seems it's important to mention
> still.
>
> There already was a fix for CVE-2026-48002 earlier:
>
> commit 46ee49034d26d04d95ba8f3183d4fbfa9d2b89b4
> Author: Daniel P. Berrangé <[email protected]>
> Date:   Thu May 21 11:33:52 2026 +0100
>
>      ui/vnc: fix OOB write in lossy rect worker code
>
> which touched the same code.  Now this one, with a
> very similar subject.
>
> Unfortunately this (additional) fix does not mention the
> previous fix, so there's some confusion about which commit
> actually fixed this issue.  It looks like the first fix was
> incomplete and this additional fix were needed.

That's correct, we reused the same CVE

Daniel P. Berrangé said on the issue:
We didn't release master yet. As long as we also didn't release any
stable branches that claimed to fix it, we could re-use it IMHO.


Reply via email to