On 2026/07/28 23:16, Ankur Saini wrote:
A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
partially initialized. If the supplied bytes set the fence flag, stale
fence metadata may later be returned to the guest.
Validate the common header length before dispatch. Clear cmd_hdr and
complete malformed requests with ERR_INVALID_PARAMETER so stale fields
cannot reach the response.
Fixes: CVE-2026-18054
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4094
Reported-by: Ankur Saini <[email protected]>
Signed-off-by: Ankur Saini <[email protected]>
Reviewed-by: Akihiko Odaki <[email protected]>
Please also fix vhost-user-gpu.
Regards,
Akihiko Odaki
---
A control request shorter than virtio_gpu_ctrl_hdr can leave cmd_hdr
partially initialized. If the supplied bytes set the fence flag, stale
fence metadata may later be returned to the guest.
Validate the common header length before dispatch. Clear cmd_hdr and
complete malformed requests with ERR_INVALID_PARAMETER so stale fields
cannot reach the response.
---
hw/display/virtio-gpu.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/hw/display/virtio-gpu.c b/hw/display/virtio-gpu.c
index 4d46a4eb10..15a845eff6 100644
--- a/hw/display/virtio-gpu.c
+++ b/hw/display/virtio-gpu.c
@@ -1105,8 +1105,14 @@ void virtio_gpu_process_cmdq(VirtIOGPU *g)
break;
}
- /* process command */
- vgc->process_cmd(g, cmd);
+ if (unlikely(iov_size(cmd->elem.out_sg, cmd->elem.out_num) <
+ sizeof(cmd->cmd_hdr))) {
+ memset(&cmd->cmd_hdr, 0, sizeof(cmd->cmd_hdr));
+ virtio_gpu_ctrl_response_nodata(
+ g, cmd, VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER);
+ } else {
+ vgc->process_cmd(g, cmd);
+ }
/* command suspended */
if (!cmd->finished && !(cmd->cmd_hdr.flags & VIRTIO_GPU_FLAG_FENCE)) {
---
base-commit: 299e7557ed15a9a325620698add379a3ce2d1d95
change-id: 20260728-virtio-gpu-short-header-476aa1dae4f7
Best regards,