On Wed, Jul 08, 2026 at 04:41:12PM +0200, Laurent Vivier wrote: > The migration restore path reads nr_active_ports from the incoming > stream and passes it directly to fetch_active_ports_list(), which > uses it to size a heap allocation. A crafted migration stream can set > this field to a very large value, causing QEMU to attempt a > multi-gigabyte allocation and abort. > > Fix this by checking nr_active_ports against the configured > max_virtserial_ports before calling fetch_active_ports_list(). > > Cc: [email protected] > Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801 > Signed-off-by: Laurent Vivier <[email protected]>
Acked-by: Michael S. Tsirkin <[email protected]> > --- > hw/char/virtio-serial-bus.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c > index c1973f0248fc..80f1b308aa53 100644 > --- a/hw/char/virtio-serial-bus.c > +++ b/hw/char/virtio-serial-bus.c > @@ -804,6 +804,10 @@ static int virtio_serial_load_device(VirtIODevice *vdev, > QEMUFile *f, > > qemu_get_be32s(f, &nr_active_ports); > > + if (nr_active_ports > max_nr_ports) { > + return -EINVAL; > + } > + > if (nr_active_ports) { > ret = fetch_active_ports_list(f, s, nr_active_ports); > if (ret) { > -- > 2.54.0
