Re: [PATCH] hw/char/virtio-serial-bus: validate nr_active_ports from migration stream

2026-07-08 Thread Laurent Vivier

On 7/9/26 07:55, Michael S. Tsirkin wrote:

On Wed, Jul 08, 2026 at 04:41:12PM +0200, Laurent Vivier wrote:

The migration restore path reads nr_active_ports from the incoming
stream and passes it directly to fetch_active_ports_list(), which
uses it to size a heap allocation. A crafted migration stream can set
this field to a very large value, causing QEMU to attempt a
multi-gigabyte allocation and abort.

Fix this by checking nr_active_ports against the configured
max_virtserial_ports before calling fetch_active_ports_list().

Cc: [email protected]


Can you add a Fixes tag pls?


Fixes: 6663a1956eb6 ("virtio-serial-bus: Maintain guest and host port open/close 
state")




Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801
Signed-off-by: Laurent Vivier 


to make sure who is merging this me?


Yes, please merge it through your tree

Thanks,
Laurent




---
  hw/char/virtio-serial-bus.c | 4 
  1 file changed, 4 insertions(+)

diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c
index c1973f0248fc..80f1b308aa53 100644
--- a/hw/char/virtio-serial-bus.c
+++ b/hw/char/virtio-serial-bus.c
@@ -804,6 +804,10 @@ static int virtio_serial_load_device(VirtIODevice *vdev, 
QEMUFile *f,
  
  qemu_get_be32s(f, &nr_active_ports);
  
+if (nr_active_ports > max_nr_ports) {

+return -EINVAL;
+}
+
  if (nr_active_ports) {
  ret = fetch_active_ports_list(f, s, nr_active_ports);
  if (ret) {
--
2.54.0







Re: [PATCH] hw/char/virtio-serial-bus: validate nr_active_ports from migration stream

2026-07-08 Thread Michael S. Tsirkin
On Wed, Jul 08, 2026 at 04:41:12PM +0200, Laurent Vivier wrote:
> The migration restore path reads nr_active_ports from the incoming
> stream and passes it directly to fetch_active_ports_list(), which
> uses it to size a heap allocation. A crafted migration stream can set
> this field to a very large value, causing QEMU to attempt a
> multi-gigabyte allocation and abort.
> 
> Fix this by checking nr_active_ports against the configured
> max_virtserial_ports before calling fetch_active_ports_list().
> 
> Cc: [email protected]

Can you add a Fixes tag pls?

> Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801
> Signed-off-by: Laurent Vivier 

to make sure who is merging this me?

> ---
>  hw/char/virtio-serial-bus.c | 4 
>  1 file changed, 4 insertions(+)
> 
> diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c
> index c1973f0248fc..80f1b308aa53 100644
> --- a/hw/char/virtio-serial-bus.c
> +++ b/hw/char/virtio-serial-bus.c
> @@ -804,6 +804,10 @@ static int virtio_serial_load_device(VirtIODevice *vdev, 
> QEMUFile *f,
>  
>  qemu_get_be32s(f, &nr_active_ports);
>  
> +if (nr_active_ports > max_nr_ports) {
> +return -EINVAL;
> +}
> +
>  if (nr_active_ports) {
>  ret = fetch_active_ports_list(f, s, nr_active_ports);
>  if (ret) {
> -- 
> 2.54.0




Re: [PATCH] hw/char/virtio-serial-bus: validate nr_active_ports from migration stream

2026-07-08 Thread Michael S. Tsirkin
On Wed, Jul 08, 2026 at 04:41:12PM +0200, Laurent Vivier wrote:
> The migration restore path reads nr_active_ports from the incoming
> stream and passes it directly to fetch_active_ports_list(), which
> uses it to size a heap allocation. A crafted migration stream can set
> this field to a very large value, causing QEMU to attempt a
> multi-gigabyte allocation and abort.
> 
> Fix this by checking nr_active_ports against the configured
> max_virtserial_ports before calling fetch_active_ports_list().
> 
> Cc: [email protected]
> Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801
> Signed-off-by: Laurent Vivier 

Acked-by: Michael S. Tsirkin 


> ---
>  hw/char/virtio-serial-bus.c | 4 
>  1 file changed, 4 insertions(+)
> 
> diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c
> index c1973f0248fc..80f1b308aa53 100644
> --- a/hw/char/virtio-serial-bus.c
> +++ b/hw/char/virtio-serial-bus.c
> @@ -804,6 +804,10 @@ static int virtio_serial_load_device(VirtIODevice *vdev, 
> QEMUFile *f,
>  
>  qemu_get_be32s(f, &nr_active_ports);
>  
> +if (nr_active_ports > max_nr_ports) {
> +return -EINVAL;
> +}
> +
>  if (nr_active_ports) {
>  ret = fetch_active_ports_list(f, s, nr_active_ports);
>  if (ret) {
> -- 
> 2.54.0




Re: [PATCH] hw/char/virtio-serial-bus: validate nr_active_ports from migration stream

2026-07-08 Thread Thomas Huth

On 08/07/2026 16.41, Laurent Vivier wrote:

The migration restore path reads nr_active_ports from the incoming
stream and passes it directly to fetch_active_ports_list(), which
uses it to size a heap allocation. A crafted migration stream can set
this field to a very large value, causing QEMU to attempt a
multi-gigabyte allocation and abort.

Fix this by checking nr_active_ports against the configured
max_virtserial_ports before calling fetch_active_ports_list().

Cc: [email protected]
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801
Signed-off-by: Laurent Vivier 
---
  hw/char/virtio-serial-bus.c | 4 
  1 file changed, 4 insertions(+)

diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c
index c1973f0248fc..80f1b308aa53 100644
--- a/hw/char/virtio-serial-bus.c
+++ b/hw/char/virtio-serial-bus.c
@@ -804,6 +804,10 @@ static int virtio_serial_load_device(VirtIODevice *vdev, 
QEMUFile *f,
  
  qemu_get_be32s(f, &nr_active_ports);
  
+if (nr_active_ports > max_nr_ports) {

+return -EINVAL;
+}
+
  if (nr_active_ports) {
  ret = fetch_active_ports_list(f, s, nr_active_ports);
  if (ret) {


Reviewed-by: Thomas Huth 




Re: [PATCH] hw/char/virtio-serial-bus: validate nr_active_ports from migration stream

2026-07-08 Thread Daniel P . Berrangé
On Wed, Jul 08, 2026 at 04:41:12PM +0200, Laurent Vivier wrote:
> The migration restore path reads nr_active_ports from the incoming
> stream and passes it directly to fetch_active_ports_list(), which
> uses it to size a heap allocation. A crafted migration stream can set
> this field to a very large value, causing QEMU to attempt a
> multi-gigabyte allocation and abort.
> 
> Fix this by checking nr_active_ports against the configured
> max_virtserial_ports before calling fetch_active_ports_list().
> 
> Cc: [email protected]
> Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801
> Signed-off-by: Laurent Vivier 
> ---
>  hw/char/virtio-serial-bus.c | 4 
>  1 file changed, 4 insertions(+)

Reviewed-by: Daniel P. Berrangé 


With regards,
Daniel
-- 
|: https://berrange.com   ~~https://hachyderm.io/@berrange :|
|: https://libvirt.org  ~~  https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~https://fstop138.berrange.com :|