@samitouri / QOSamiQemu / commits / d7913fac77

s390x/sclp: pv: only copy the original SCCB buffer

With variable length and EXTENDED_LENGTH_SCCB, some callbacks might change the length field. For example read SCP info might write a new length into the SCCB header. We must not use that new length for the buffer copy, since the buffer was allocated with the original length. Only the length field in the work SCCB is changed, to indicate the "necessary" size. Using the new length reads past the allocation, so tools like ASAN might detect a buffer overrun. Secure guests do not have EXTENDED_LENGTH_SCCB, and the ultravisor checks and sanitizes the length field, so no qemu heap contents are exposed to the guest and the non pv-path already has the same header.length. Fixes: 0f73c5b30b8b ("s390x: protvirt: SCLP interpretation") Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com> Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com> Reviewed-by: Eric Farman <farman@linux.ibm.com> Link: https://lore.kernel.org/qemu-devel/20260814125857.1729543-1-borntraeger@de.ibm.com Signed-off-by: Eric Farman <farman@linux.ibm.com>

Christian Borntraeger committed Aug 14, 2026 at 14:58 UTC d7913fac774706a02faef0dc1c4c19df65a5a379
1 file changed +1 -1
hw/s390x/sclp.c
+1 -1
@@ -287,7 +287,7 @@ int sclp_service_call_protected(S390CPU *cpu, uint64_t sccb, uint32_t code)
287 sclp_c->execute(sclp, work_sccb, code);
288 out_write:
289 s390_cpu_pv_mem_write(env_archcpu(env), 0, work_sccb,
290 - be16_to_cpu(work_sccb->h.length));
290 + be16_to_cpu(header.length));
291 sclp_c->service_interrupt(sclp, SCLP_PV_DUMMY_ADDR);
292 return 0;
293 }