已合并
Fix CVE-2026-63321/CVE-2026-63320/CVE-2026-3890/CVE-2026-8343 #2031
aven6创建于 8月29日
Fix CVE-2026-63321/CVE-2026-63320/CVE-2026-3890/CVE-2026-8343 #2031
已合并
共 3 个文件变更+38-2
| @@ -1657,10 +1657,21 @@ static int receive_filter(VirtIONet *n, const uint8_t *buf, int size) | |||
| 1657 | if (n->promisc) | 1657 | if (n->promisc) |
| 1658 | return 1; | 1658 | return 1; |
| 1659 | 1659 | ||
| 1660 | + if (size < n->host_hdr_len + 14) { | ||
| 1661 | + /* Truncated ethernet packet */ | ||
| 1662 | + return 0; | ||
| 1663 | + } | ||
| 1664 | + | ||
| 1660 | ptr += n->host_hdr_len; | 1665 | ptr += n->host_hdr_len; |
| 1661 | 1666 | ||
| 1662 | if (!memcmp(&ptr[12], vlan, sizeof(vlan))) { | 1667 | if (!memcmp(&ptr[12], vlan, sizeof(vlan))) { |
| 1663 | - int vid = lduw_be_p(ptr + 14) & 0xfff; | 1668 | + int vid; |
| 1669 | + | ||
| 1670 | + /* Truncated vlan packet */ | ||
| 1671 | + if (size < n->host_hdr_len + 16) { | ||
| 1672 | + return 0; | ||
| 1673 | + } | ||
| 1674 | + vid = lduw_be_p(ptr + 14) & 0xfff; | ||
| 1664 | if (!(n->vlans[vid >> 5] & (1U << (vid & 0x1f)))) | 1675 | if (!(n->vlans[vid >> 5] & (1U << (vid & 0x1f)))) |
| 1665 | return 0; | 1676 | return 0; |
| 1666 | } | 1677 | } |
| @@ -2547,6 +2558,13 @@ static ssize_t virtio_net_receive(NetClientState *nc, const uint8_t *buf, | |||
| 2547 | { | 2558 | { |
| 2548 | VirtIONet *n = qemu_get_nic_opaque(nc); | 2559 | VirtIONet *n = qemu_get_nic_opaque(nc); |
| 2549 | if ((n->rsc4_enabled || n->rsc6_enabled)) { | 2560 | if ((n->rsc4_enabled || n->rsc6_enabled)) { |
| 2561 | + /* this never happens with existing backends, but just in case. */ | ||
| 2562 | + if (n->host_hdr_len != n->guest_hdr_len) { | ||
| 2563 | + warn_report_once("virtio-net: host_hdr_len %zu != guest_hdr_len %zu, " | ||
| 2564 | + "skipping RSC", | ||
| 2565 | + n->host_hdr_len, n->guest_hdr_len); | ||
| 2566 | + return virtio_net_do_receive(nc, buf, size); | ||
| 2567 | + } | ||
| 2550 | return virtio_net_rsc_receive(nc, buf, size); | 2568 | return virtio_net_rsc_receive(nc, buf, size); |
| 2551 | } else { | 2569 | } else { |
| 2552 | return virtio_net_do_receive(nc, buf, size); | 2570 | return virtio_net_do_receive(nc, buf, size); |
| @@ -1023,6 +1023,17 @@ static int ohci_service_td(OHCIState *ohci, struct ohci_ed *ed) | |||
| 1023 | if (len && dir != OHCI_TD_DIR_IN) { | 1023 | if (len && dir != OHCI_TD_DIR_IN) { |
| 1024 | /* The endpoint may not allow us to transfer it all now */ | 1024 | /* The endpoint may not allow us to transfer it all now */ |
| 1025 | pktlen = (ed->flags & OHCI_ED_MPS_MASK) >> OHCI_ED_MPS_SHIFT; | 1025 | pktlen = (ed->flags & OHCI_ED_MPS_MASK) >> OHCI_ED_MPS_SHIFT; |
| 1026 | + /* | ||
| 1027 | + * The OHCI spec does not say what to do if the guest hands us | ||
| 1028 | + * an endpoint descriptor which specifies a MaximumPacketSize | ||
| 1029 | + * of zero, which would mean we can never actually make forward | ||
| 1030 | + * progress transferring data to it. We choose to treat it as | ||
| 1031 | + * an error. | ||
| 1032 | + */ | ||
| 1033 | + if (pktlen == 0) { | ||
| 1034 | + ohci_die(ohci); | ||
| 1035 | + return 1; | ||
| 1036 | + } | ||
| 1026 | if (pktlen > len) { | 1037 | if (pktlen > len) { |
| 1027 | pktlen = len; | 1038 | pktlen = len; |
| 1028 | } | 1039 | } |
| @@ -24,6 +24,7 @@ | |||
| 24 | 24 | ||
| 25 | 25 | ||
| 26 | 26 | ||
| 27 | + | ||
| 27 | 28 | ||
| 28 | 29 | ||
| 29 | 30 | ||
| @@ -270,10 +271,16 @@ void vnc_client_cut_text_ext(VncState *vs, int32_t len, uint32_t flags, uint8_t | |||
| 270 | buf && size >= 4) { | 271 | buf && size >= 4) { |
| 271 | uint32_t tsize = read_u32(buf, 0); | 272 | uint32_t tsize = read_u32(buf, 0); |
| 272 | uint8_t *tbuf = buf + 4; | 273 | uint8_t *tbuf = buf + 4; |
| 273 | - if (tsize < size) { | 274 | + if (tsize <= size - 4) { |
| 274 | qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo, | 275 | qemu_clipboard_set_data(&vs->cbpeer, vs->cbinfo, |
| 275 | QEMU_CLIPBOARD_TYPE_TEXT, | 276 | QEMU_CLIPBOARD_TYPE_TEXT, |
| 276 | tsize, tbuf, true); | 277 | tsize, tbuf, true); |
| 278 | + } else { | ||
| 279 | + error_report("vnc: malformed extended clipboard payload " | ||
| 280 | + "with text length %u exceeding available %u", | ||
| 281 | + tsize, size - 4); | ||
| 282 | + vnc_client_error(vs); | ||
| 283 | + return; | ||
| 277 | } | 284 | } |
| 278 | } | 285 | } |
| 279 | } | 286 | } |