On Mon, Jul 27 2026, Christian Borntraeger <[email protected]> wrote:

> Cornelia, Eric, Matt,
>
> here are 5 more fixes for hardening QEMU against invalid input. Nothing
> is strictly a security issues as defined in the policy. For example
> https://qemu-project.gitlab.io/qemu/system/security.html says assert /
> abort: If triggering the code path requires kernel privileges (or root
> account access) in the guest, asserts/aborts in QEMU are a self
> inflicted denial of service. These will not be treated as security
> flaws, at most hardening bugs.
> And if anyone can provide invalid boot loader content it can provide
> anything to boot if secure boot is not available.
> We should fix those anyway, probably even for 11.1 

Fixing: yes. For 11.1: how easy are they to trigger? For the bios fixes,
I assume you need a broken/crafted disk image; I assume that for the
other two, you need some buggy/misbehaving guest. Did you actually
manage to trigger this via some kind of test case?

>
> Conny, I did not rebuild the s390-ccw, I assume you will do that?

Yes, the bios rebuild will be done by whoever ends up applying the
patches.

>
> Christian Borntraeger (1):
>   hw/char/sclpconsole-lm: avoid guest triggerable assert
>
> Joshua Daley (4):
>   s390x/ipl: validate num_comp against iplb length before iterating
>   pc-bios/s390-ccw: fix out-of-bounds read in iso_get_file_size()
>   pc-bios/s390-ccw: bounds-check zipl menu entry index before array
>     write
>   pc-bios/s390-ccw: bound zipl menu strlen and replace VLA in
>     zipl_print_entry
>
>  hw/char/sclpconsole-lm.c    |  3 ++-
>  hw/s390x/ipl.h              |  6 ++++++
>  pc-bios/s390-ccw/bootmap.c  |  6 ++++--
>  pc-bios/s390-ccw/helper.h   | 10 ++++++++++
>  pc-bios/s390-ccw/menu.c     | 36 +++++++++++++++++++++++++++++-------
>  pc-bios/s390-ccw/s390-ccw.h |  2 +-
>  6 files changed, 52 insertions(+), 11 deletions(-)


Reply via email to