@samitouri / QOSamiQemu / commits / cfda94eddb

block/vmdk: fix OOB read in vmdk_read_extent()

Bounds check for marker.size doesn't account for the 12-byte marker header, allowing zlib to read past the allocated buffer. Move the check inside the has_marker block and subtract the marker size. Fixes: CVE-2026-2243 Reported-by: Halil Oktay (oblivionsage) <cookieandcream560@gmail.com> Signed-off-by: Halil Oktay (oblivionsage) <cookieandcream560@gmail.com> Reviewed-by: Kevin Wolf <kwolf@redhat.com> Signed-off-by: Kevin Wolf <kwolf@redhat.com>

Halil Oktay (oblivionsage) committed Feb 10, 2026 at 13:33 UTC cfda94eddb6c9c49b66461c950b22845a46a75c9
1 file changed +4 -4
block/vmdk.c
+4 -4
@@ -1951,10 +1951,10 @@ vmdk_read_extent(VmdkExtent *extent, int64_t cluster_offset,
1951 marker = (VmdkGrainMarker *)cluster_buf;
1952 compressed_data = marker->data;
1953 data_len = le32_to_cpu(marker->size);
1954 - }
1955 - if (!data_len || data_len > buf_bytes) {
1956 - ret = -EINVAL;
1957 - goto out;
1954 + if (!data_len || data_len > buf_bytes - sizeof(VmdkGrainMarker)) {
1955 + ret = -EINVAL;
1956 + goto out;
1957 + }
1958 }
1959 ret = uncompress(uncomp_buf, &buf_len, compressed_data, data_len);
1960 if (ret != Z_OK) {