已合并
Fix CVE-2026-63321/CVE-2026-63320/CVE-2026-3890/CVE-2026-8343 #2031
aven6创建于 8月29日
Fix CVE-2026-63321/CVE-2026-63320/CVE-2026-3890/CVE-2026-8343 #2031
已合并
aven6创建于 8月29日
aven6成员
8月29日

Fix
CVE-2026-63321: openEuler尚未识别到
64a6a336f4 ("virtio: add support for negotiating extended features") 在openEuler qemu-8.2.0 不存在,该CVE fix补丁 a6e0519ea8ed6fc84fab9bf9ca82c7a55780f880( virtio: use masked features with set_features_ex) 不回合,只回合 52c7bb369b23dfcafb6e6d90665c777797b55e88 ( virtio-net: fix OOB read in RSC receive path)

CVE-2026-63320: openEuler尚未识别到
CVE-2026-3890: https://atomgit.com/src-openeuler/qemu/issues/372
CVE-2026-8343: https://atomgit.com/src-openeuler/qemu/issues/370

likedislike
Pull Request已成功合入, 合并人@openeuler-ci-bot
(感谢 aven6 的贡献)
Aaven6成员
8月29日 创建了 pull request,commit e1e828be
Aaven6成员
8月29日 关联了issue:CVE-2026-8343,CVE-2026-3890
atomgit-bot
atomgit-bot
8月29日 评论:

变更摘要

本 PR 针对 QEMU 6.2.0 分支修复四个 CVE 漏洞(CVE-2026-63321、CVE-2026-63320、CVE-2026-3890、CVE-2026-8343),核心改动集中在三处:为 virtio-net 的收包过滤与 RSC 路径补充长度边界校验,为 OHCI 主机控制器在端点 MaximumPacketSize 为 0 时增加错误处理,并修正 VNC 扩展剪贴板报文的长度校验逻辑,防止恶意/畸形报文引发越界读取或异常行为。

主要改动

  • virtio-net 收包长度校验:在 receive_filter 中,对截断的以太网报文(size < n->host_hdr_len + 14)以及截断的 VLAN 报文(size < n->host_hdr_len + 16)直接返回 0 拒绝接收,避免越界读取。
  • virtio-net RSC 路径防护:在 virtio_net_receive 中,当 n->host_hdr_len 与 n->guest_hdr_len 不一致时,通过 warn_report_once 告警并回退到 virtio_net_do_receive,跳过 RSC 处理以防异常。
  • OHCI 零长度 MPS 处理:在 ohci_service_td 中,当端点描述符的 MaximumPacketSize(pktlen)为 0 时调用 ohci_die 使控制器进入错误状态并返回,避免无法推进数据传输导致的挂死。
  • VNC 扩展剪贴板校验修正:在 vnc_client_cut_text_ext 中,将文本长度判断由 tsize < size 改为 tsize <= size - 4(考虑 4 字节长度头),畸形负载时输出 error_report 日志并通过 vnc_client_error 断开客户端连接。
likedislike
不准确?
atomgit-bot
atomgit-bot
8月29日 评论:

代码审查

✅ 未发现问题

likedislike
不准确?
openeuler-ci-botopeneuler-ci-bot成员
8月29日 将Chuan-Zheng,kevinzhu1,imxcc,cellfaint,flyking001,RootWB设为审查人
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:sig/Virt
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:

Welcome To openEuler Community

Hey @aven6 , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands. You can self-configure the PR merge rules for this repository. For more details, please refer to Here.

Contact Guide

If you have any questions, please contact the SIG: Virt ,
and any of the maintainers: @Chuan-Zheng, @RootWB, @cellfaint, @flyking001, @imxcc, @kevinzhu1 ,
and any of the committers: @aven6, @eillon, @huang987246510, @yebiaoxiang, @zhangliang5 .

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:stat/needs-squash
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:openeuler-cla/yes
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:

CLA Signature Pass

aven6, thanks for your pull request. All authors of the commits have signed the CLA. 👍

likedislike
Aaven6成员
8月29日 修改了pull request 的描述
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:ci_processing
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:

门禁正在运行, 您可以通过以下链接查看实时门禁检查结果.
若您对门禁结果含义不清晰或者遇到问题不知如何解决,可参考门禁指导手册
门禁入口及编码规范检查: multiarch/openeuler/trigger/qemu/1116/console

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 删除了label:ci_processing
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:
Check Name Build Result 详情 Build Details
check_sca ⚠WARNING • SCA检查发现未确认的开源组件问题,请查看报告: https://www.openlibing.com/apps/personalScandTaskInfor/person/31bae763-a0e4-43fa-b4a8-541ce8ae127b?projectId=300024&codeHostingPlatformFlag=gitcode #1116
check_code ❌FAILED • CodeCheck检查发现代码缺陷,请查看报告: https://www.openlibing.com/apps/entryCheckDashCode/MR_f5bb127e27b3443f8f76c57dcb104933/8845f9247832be6211ea559942b1c2ce?projectId=300024&codeHostingPlatformFlag=gitcode
check_package_license ✅SUCCESS
x86_64 check_build ✅SUCCESS #1112
aarch64 check_build ✅SUCCESS #1095
likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:ci_failed
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:
likedislike
aven6成员
8月29日 评论:

/retest

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 删除了label:ci_failed
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:ci_processing
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:

门禁正在运行, 您可以通过以下链接查看实时门禁检查结果.
若您对门禁结果含义不清晰或者遇到问题不知如何解决,可参考门禁指导手册
门禁入口及编码规范检查: multiarch/openeuler/trigger/qemu/1118/console

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 删除了label:ci_processing
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:
Check Name Build Result 详情 Build Details
check_sca ⚠WARNING • SCA检查发现未确认的开源组件问题,请查看报告: https://www.openlibing.com/apps/personalScandTaskInfor/person/06ee7ed1-5303-4592-8429-db5f64d92f07?projectId=300024&codeHostingPlatformFlag=gitcode #1118
check_code ✅SUCCESS
check_package_license ✅SUCCESS
x86_64 check_build ✅SUCCESS #1114
aarch64 check_build ✅SUCCESS #1097
likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:ci_successful
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:
likedislike
yebiaoxiang成员
8月29日 评论:

/lgtm
/approve

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 添加了label:approvedlgtm
openeuler-ci-bot
openeuler-ci-bot成员
8月29日 评论:

Review Code Feedback

  • The label lgtm, approved was added to this pull request. It means that yebiaoxiang reviewed the code changes. 👋
Tips
  • If this pull request is not merged while all conditions are met, comment /check-pr to try again. 😄
likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月29日 合入了pull request,合并节点 SHA:3f8d8be94726278ea396ad53128a60eda8550887