@samitouri / QOSamiQemu / commits / e56b4bbff1

ui: fix validation of VNC extended clipboard data length

QEMU's VNC extended clipboard handler inflates a client-controlled compressed clipboard payload. The code checks the declared text size against the total inflated buffer size: if (tsize < size) but then copies from: tbuf = buf + 4; qemu_clipboard_set_data(..., tsize, tbuf, true); The correct bound is the remaining data length after the 4-byte length field, not the total inflated buffer length. As a result, a VNC client can make QEMU copy up to 3 bytes past the end of the inflated heap buffer. With a second VNC client, those copied bytes are observable through the normal VNC extended clipboard PROVIDE path. Fixes: CVE-2026-8343 Reported-by: Heechan Kang <gganji11@naver.com> Reported-by: Feifan Qian <bea1e@proton.me> Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> Signed-off-by: Heechan Kang <gganji11@naver.com> [DB: added #include and 'return' statements] Signed-off-by: Daniel P. Berrangé <berrange@redhat.com> Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com> Message-ID: <20260512095543.459949-1-berrange@redhat.com>

Heechan Kang committed May 12, 2026 at 10:55 UTC e56b4bbff1df260487b80abe1f967f687fa115d3
1 file changed +8 -1
ui/vnc-clipboard.c
+8 -1
@@ -23,6 +23,7 @@
23 */
24
25 #include "qemu/osdep.h"
26 +#include "qemu/error-report.h"
27 #include "vnc.h"
28 #include "vnc-jobs.h"
29
@@ -282,10 +283,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t len, uint32_t flags, uint8_t
283 buf && size >= 4) {
284 uint32_t tsize = read_u32(buf, 0);
285 uint8_t *tbuf = buf + 4;
285 - if (tsize < size) {
286 + if (tsize <= size - 4) {
287 qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo,
288 QEMU_CLIPBOARD_TYPE_TEXT,
289 tsize, tbuf, true);
290 + } else {
291 + error_report("vnc: malformed extended clipboard payload "
292 + "with text length %u exceeding available %u",
293 + tsize, size - 4);
294 + vnc_client_error(vs);
295 + return;
296 }
297 }
298 }