On 08/07/2026 16.41, Laurent Vivier wrote:
The migration restore path reads nr_active_ports from the incoming
stream and passes it directly to fetch_active_ports_list(), which
uses it to size a heap allocation. A crafted migration stream can set
this field to a very large value, causing QEMU to attempt a
multi-gigabyte allocation and abort.
Fix this by checking nr_active_ports against the configured
max_virtserial_ports before calling fetch_active_ports_list().
Cc: [email protected]
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801
Signed-off-by: Laurent Vivier <[email protected]>
---
hw/char/virtio-serial-bus.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c
index c1973f0248fc..80f1b308aa53 100644
--- a/hw/char/virtio-serial-bus.c
+++ b/hw/char/virtio-serial-bus.c
@@ -804,6 +804,10 @@ static int virtio_serial_load_device(VirtIODevice *vdev,
QEMUFile *f,
qemu_get_be32s(f, &nr_active_ports);
+ if (nr_active_ports > max_nr_ports) {
+ return -EINVAL;
+ }
+
if (nr_active_ports) {
ret = fetch_active_ports_list(f, s, nr_active_ports);
if (ret) {
Reviewed-by: Thomas Huth <[email protected]>