On 7/27/26 7:50 AM, Christian Borntraeger wrote:
> From: Joshua Daley <[email protected]>
> 
> In ipl_valid_pv_components(), the upper bound of the for loop,
> ipib_pv->num_comp, is read from guest memory. Before iterating, verify
> that its value will not cause a read beyond the end of the
> IplParameterBlock.
> 
> Fixes: c3347ed0d2ee42a7 ("s390x: protvirt: Support unpack facility")
> Signed-off-by: Joshua Daley <[email protected]>
> Reviewed-by: Christian Borntraeger <[email protected]>

Reviewed-by: Matthew Rosato <[email protected]>

> ---
>  hw/s390x/ipl.h | 6 ++++++
>  1 file changed, 6 insertions(+)
> 
> diff --git a/hw/s390x/ipl.h b/hw/s390x/ipl.h
> index fac30763df..ef9c063d90 100644
> --- a/hw/s390x/ipl.h
> +++ b/hw/s390x/ipl.h
> @@ -124,6 +124,12 @@ static inline bool 
> ipl_valid_pv_components(IplParameterBlock *iplb)
>          return false;
>      }
>  
> +    if (offsetof(IplParameterBlock, pv.components) +
> +        ipib_pv->num_comp * sizeof(IPLBlockPVComp) >
> +        be32_to_cpu(iplb->len)) {
> +        return false;
> +    }
> +
>      for (i = 0; i < ipib_pv->num_comp; i++) {
>          /* Addr must be 4k aligned */
>          if (ipib_pv->components[i].addr & ~TARGET_PAGE_MASK) {


Reply via email to