vhost-user-gpu: fix integer overflow in buffer allocation
A malicious guest can trigger a heap buffer overflow in the vhost-user-gpu backend by sending a VIRTIO_GPU_CMD_RESOURCE_CREATE_2D with large width and height values (e.g. 65537x65537). The allocation size width * height * 4 silently wraps in uint32_t arithmetic, resulting in a much smaller allocation than expected. Subsequent VIRTIO_GPU_CMD_TRANSFER_TO_HOST_2D writes past the heap buffer. The in-tree virtio-gpu device (hw/display/virtio-gpu.c) already handles this via calc_image_hostmem() with uint64_t arithmetic and an overflow check. Apply the same approach to the vhost-user-gpu contrib backend: - Add an overflow check in vugbm_buffer_create() rejecting dimensions where width * height * 4 exceeds UINT32_MAX - Promote the size arithmetic to uint64_t in mem_alloc_bo() and udmabuf_get_size() - Check the return value of vugbm_buffer_create() in vg_resource_create_2d(), which was previously ignored Fixes: CVE-2026-15264 Reported-by: "Vulnerability Report" <vr@darknavy.com> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3940 Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com> Acked-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com> Message-ID: <20260710134720.2317856-1-marcandre.lureau@redhat.com>