On Fri, Sep 11, 2026 at 02:50:27PM +0000, admin wrote: > Thanks Michael for the review. Merci Marc-André! > Let me know if I can support in any ways shape or form in other such work. > Best, > Martin Brodeur
Sorry I dropped this for now, I think Marc-André is better suited to merge them. > > > > On Thursday, September 10th, 2026 at 4:13 PM, Michael S. Tsirkin > <[email protected]> wrote: > > > From: Marc-André Lureau <[email protected]> > > > > virgl_cmd_submit_3d() passes the guest-controlled cs.size directly to > > g_malloc() without any bounds check. A malicious guest can set this > > field to an arbitrarily large value (up to 4GB), causing an OOM abort > > that crashes the vhost-user-gpu daemon. > > > > Validate cs.size against the actual descriptor payload size before > > allocating, rejecting values that exceed what the virtqueue entry > > can carry. > > > > Fixes: d52c454aadc ("contrib: add vhost-user-gpu") > > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3776 > > Reported-by: [email protected] > > Signed-off-by: Marc-André Lureau <[email protected]> > > Reviewed-by: Michael S. Tsirkin <[email protected]> > > Signed-off-by: Michael S. Tsirkin <[email protected]> > > Message-ID: <[email protected]> > > --- > > contrib/vhost-user-gpu/virgl.c | 12 ++++++++---- > > 1 file changed, 8 insertions(+), 4 deletions(-) > > > > diff --git a/contrib/vhost-user-gpu/virgl.c b/contrib/vhost-user-gpu/virgl.c > > index 20bae57d0f..c95c4afc5c 100644 > > --- a/contrib/vhost-user-gpu/virgl.c > > +++ b/contrib/vhost-user-gpu/virgl.c > > @@ -197,20 +197,24 @@ virgl_cmd_submit_3d(VuGpu *g, > > struct virtio_gpu_ctrl_command *cmd) > > { > > struct virtio_gpu_cmd_submit cs; > > + size_t iov_len; > > void *buf; > > size_t s; > > > > VUGPU_FILL_CMD(cs); > > > > - if (cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { > > - g_critical("%s: command buffer too large (%u)", > > - __func__, cs.size); > > + iov_len = iov_size(cmd->elem.out_sg, cmd->elem.out_num); > > + if (cs.size == 0 || iov_len < sizeof(cs) || > > + cs.size > iov_len - sizeof(cs) || > > + cs.size > VIRTIO_GPU_MAX_CMD_SUBMIT_SIZE) { > > + g_critical("%s: size out of range (%u/%zu)", > > + __func__, cs.size, iov_len); > > cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_PARAMETER; > > return; > > } > > > > buf = g_try_malloc(cs.size); > > - if (!buf && cs.size) { > > + if (!buf) { > > cmd->error = VIRTIO_GPU_RESP_ERR_OUT_OF_MEMORY; > > return; > > } > > -- > > MST > > > >
