On Mon, Jul 27, 2026 at 05:45:47AM -0700, 김승중 wrote:
> The inflight buffer size is migrated as a uint64_t, but vmstate_size()
> reads VMS_VBUFFER sizes as int32_t. Values above INT32_MAX therefore
> become negative and are converted to a very large size_t while loading
> the buffer, allowing writes beyond the smaller memfd-backed mapping.
> 
> Reject sizes that cannot be represented by vmstate_size() before
> allocating the destination buffer.
> 
> Fixes: CVE-2026-6426

This CVE really shouldn't be there.

> Reported-by: Seungjung Kim <[email protected]>
> Signed-off-by: Seungjung Kim <[email protected]>

This doen't fix it properly, it only fixes values 2g to 4g, but above 4g
is still wrong.

A better fix here:
https://lore.kernel.org/all/9e2d0b03a60642236e6df8edde7b3562f5f9849f.1785101237.git....@redhat.com/

> 
> diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c
> index af41841b52..82eb9407ae 100644
> --- a/hw/virtio/vhost.c
> +++ b/hw/virtio/vhost.c
> @@ -2022,11 +2022,18 @@ void vhost_get_features_ex(struct vhost_dev *hdev,
>  static bool vhost_inflight_buffer_pre_load(void *opaque, Error **errp)
>  {
>      struct vhost_inflight *inflight = opaque;
> -
>      int fd = -1;

pls don't make unrelated changes like this.

> -    void *addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> -                                  F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> -                                  &fd, errp);
> +    void *addr;
> +
> +    if (inflight->size > INT32_MAX) {
> +        error_setg(errp, "inflight buffer size %" PRIu64
> +                   " exceeds maximum %d", inflight->size, INT32_MAX);
> +        return false;
> +    }
> +
> +    addr = qemu_memfd_alloc("vhost-inflight", inflight->size,
> +                            F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL,
> +                            &fd, errp);
>      if (!addr) {
>          return false;
>      }
> -- 
> 2.50.1 (Apple Git-155)


Reply via email to