@samitouri / QOSamiQemu / commits / 9f436938c5

hw/display/qxl: validate monitors_config heads[] in phys2virt

The qxl_phys2virt() call for guest_monitors_config only validates sizeof(QXLMonitorsConfig), which covers the fixed header (count and max_allowed) since commit 8efec0ef8bbc ("hw/display/qxl: Pass requested buffer size to qxl_phys2virt()"), but not the flexible array member heads[]. When count == 1, heads[0] is accessed without its memory being validated, allowing a guest to cause an out-of-bounds read. Include sizeof(QXLHead) in the size passed to qxl_phys2virt() so that the first head entry is validated within the guest memory slot, preventing guest-visible memory reading. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4027 Reported-by: Tristan @TristanInSec Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com> Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com> Message-ID: <20260715072722.1643289-1-marcandre.lureau@redhat.com> Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

Marc-André Lureau committed Jul 15, 2026 at 11:27 UTC 9f436938c52125324e36cf9c13b877aa8aada096
1 file changed +1 -1
hw/display/qxl.c
+1 -1
@@ -270,7 +270,7 @@ static void qxl_spice_monitors_config_async(PCIQXLDevice *qxl, int replay)
270 }
271
272 cfg = qxl_phys2virt(qxl, qxl->guest_monitors_config, MEMSLOT_GROUP_GUEST,
273 - sizeof(QXLMonitorsConfig));
273 + sizeof(QXLMonitorsConfig) + sizeof(QXLHead));
274 if (cfg != NULL && cfg->count == 1) {
275 qxl->guest_primary.resized = 1;
276 qxl->guest_head0_width = cfg->heads[0].width;