已合并
Fix CVE-2026-63321/CVE-2026-63320/CVE-2026-3890/CVE-2026-8343 #2031
aven6创建于 8月29日
Fix CVE-2026-63321/CVE-2026-63320/CVE-2026-3890/CVE-2026-8343 #2031
已合并
aven6创建于 8月29日
共 3 个文件变更+38-2
@@ -1657,10 +1657,21 @@ static int receive_filter(VirtIONet *n, const uint8_t *buf, int size)
1657 if (n->promisc)1657 if (n->promisc)
1658 return 1;1658 return 1;
1659 1659 
1660+ if (size < n->host_hdr_len + 14) {
1661+ /* Truncated ethernet packet */
1662+ return 0;
1663+ }
1664+ 
1660 ptr += n->host_hdr_len;1665 ptr += n->host_hdr_len;
1661 1666 
1662 if (!memcmp(&ptr[12], vlan, sizeof(vlan))) {1667 if (!memcmp(&ptr[12], vlan, sizeof(vlan))) {
1663- int vid = lduw_be_p(ptr + 14) & 0xfff;1668+ int vid;
1669+ 
1670+ /* Truncated vlan packet */
1671+ if (size < n->host_hdr_len + 16) {
1672+ return 0;
1673+ }
1674+ vid = lduw_be_p(ptr + 14) & 0xfff;
1664 if (!(n->vlans[vid >> 5] & (1U << (vid & 0x1f))))1675 if (!(n->vlans[vid >> 5] & (1U << (vid & 0x1f))))
1665 return 0;1676 return 0;
1666 }1677 }
@@ -2547,6 +2558,13 @@ static ssize_t virtio_net_receive(NetClientState *nc, const uint8_t *buf,
2547{2558{
2548 VirtIONet *n = qemu_get_nic_opaque(nc);2559 VirtIONet *n = qemu_get_nic_opaque(nc);
2549 if ((n->rsc4_enabled || n->rsc6_enabled)) {2560 if ((n->rsc4_enabled || n->rsc6_enabled)) {
2561+ /* this never happens with existing backends, but just in case. */
2562+ if (n->host_hdr_len != n->guest_hdr_len) {
2563+ warn_report_once("virtio-net: host_hdr_len %zu != guest_hdr_len %zu, "
2564+ "skipping RSC",
2565+ n->host_hdr_len, n->guest_hdr_len);
2566+ return virtio_net_do_receive(nc, buf, size);
2567+ }
2550 return virtio_net_rsc_receive(nc, buf, size);2568 return virtio_net_rsc_receive(nc, buf, size);
2551 } else {2569 } else {
2552 return virtio_net_do_receive(nc, buf, size);2570 return virtio_net_do_receive(nc, buf, size);
@@ -1023,6 +1023,17 @@ static int ohci_service_td(OHCIState *ohci, struct ohci_ed *ed)
1023 if (len && dir != OHCI_TD_DIR_IN) {1023 if (len && dir != OHCI_TD_DIR_IN) {
1024 /* The endpoint may not allow us to transfer it all now */1024 /* The endpoint may not allow us to transfer it all now */
1025 pktlen = (ed->flags & OHCI_ED_MPS_MASK) >> OHCI_ED_MPS_SHIFT;1025 pktlen = (ed->flags & OHCI_ED_MPS_MASK) >> OHCI_ED_MPS_SHIFT;
1026+ /*
1027+ * The OHCI spec does not say what to do if the guest hands us
1028+ * an endpoint descriptor which specifies a MaximumPacketSize
1029+ * of zero, which would mean we can never actually make forward
1030+ * progress transferring data to it. We choose to treat it as
1031+ * an error.
1032+ */
1033+ if (pktlen == 0) {
1034+ ohci_die(ohci);
1035+ return 1;
1036+ }
1026 if (pktlen > len) {1037 if (pktlen > len) {
1027 pktlen = len;1038 pktlen = len;
1028 }1039 }
@@ -24,6 +24,7 @@
24 24 
25#include "qemu/osdep.h"25#include "qemu/osdep.h"
26#include "qemu-common.h"26#include "qemu-common.h"
27+#include "qemu/error-report.h"
27#include "vnc.h"28#include "vnc.h"
28#include "vnc-jobs.h"29#include "vnc-jobs.h"
29 30 
@@ -270,10 +271,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t len, uint32_t flags, uint8_t
270 buf && size >= 4) {271 buf && size >= 4) {
271 uint32_t tsize = read_u32(buf, 0);272 uint32_t tsize = read_u32(buf, 0);
272 uint8_t *tbuf = buf + 4;273 uint8_t *tbuf = buf + 4;
273- if (tsize < size) {274+ if (tsize <= size - 4) {
274 qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo,275 qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo,
275 QEMU_CLIPBOARD_TYPE_TEXT,276 QEMU_CLIPBOARD_TYPE_TEXT,
276 tsize, tbuf, true);277 tsize, tbuf, true);
278+ } else {
279+ error_report("vnc: malformed extended clipboard payload "
280+ "with text length %u exceeding available %u",
281+ tsize, size - 4);
282+ vnc_client_error(vs);
283+ return;
277 }284 }
278 }285 }
279 }286 }