On 7/27/26 7:50 AM, Christian Borntraeger wrote: > From: Joshua Daley <[email protected]> > > In ipl_valid_pv_components(), the upper bound of the for loop, > ipib_pv->num_comp, is read from guest memory. Before iterating, verify > that its value will not cause a read beyond the end of the > IplParameterBlock. > > Fixes: c3347ed0d2ee42a7 ("s390x: protvirt: Support unpack facility") > Signed-off-by: Joshua Daley <[email protected]> > Reviewed-by: Christian Borntraeger <[email protected]>
Reviewed-by: Matthew Rosato <[email protected]> > --- > hw/s390x/ipl.h | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/hw/s390x/ipl.h b/hw/s390x/ipl.h > index fac30763df..ef9c063d90 100644 > --- a/hw/s390x/ipl.h > +++ b/hw/s390x/ipl.h > @@ -124,6 +124,12 @@ static inline bool > ipl_valid_pv_components(IplParameterBlock *iplb) > return false; > } > > + if (offsetof(IplParameterBlock, pv.components) + > + ipib_pv->num_comp * sizeof(IPLBlockPVComp) > > + be32_to_cpu(iplb->len)) { > + return false; > + } > + > for (i = 0; i < ipib_pv->num_comp; i++) { > /* Addr must be 4k aligned */ > if (ipib_pv->components[i].addr & ~TARGET_PAGE_MASK) {
