2 changed files with 73 additions and 1 deletions
@ -0,0 +1,68 @@ |
|||||
|
From 996eeabc0953d349b68cd29ea77fa1d7f55859f9 Mon Sep 17 00:00:00 2001 |
||||
|
Message-ID: <996eeabc0953d349b68cd29ea77fa1d7f55859f9.1788184814.git.jdenemar@redhat.com> |
||||
|
From: Peter Krempa <pkrempa@redhat.com> |
||||
|
Date: Wed, 12 Aug 2026 16:51:58 +0200 |
||||
|
Subject: [PATCH] remote: Fix integer overflow in RPC handler for |
||||
|
virNodeGetFreePages (CVE-2026-18917) |
||||
|
MIME-Version: 1.0 |
||||
|
Content-Type: text/plain; charset=UTF-8 |
||||
|
Content-Transfer-Encoding: 8bit |
||||
|
|
||||
|
CVE-2026-18917 |
||||
|
|
||||
|
The RPC handler 'remoteDispatchNodeGetFreePages' multiplies the 'npages' |
||||
|
argument with the 'cellcount' argument passed to 'virNodeGetFreePages', |
||||
|
both of which are declared as 'unsigned int' to both do an RPC limit |
||||
|
check against the 'REMOTE_NODE_MAX_CELLS' constant and then to allocate |
||||
|
the memory to hold the result from the actual hypervisor driver. |
||||
|
|
||||
|
Since both the values are 'unsigned int' the product is also unsigned |
||||
|
int so big enough numbers can overflow, both passing the check and also |
||||
|
allocating not enough memory for the result. The hypervisor driver |
||||
|
assumes that the passed buffer is large enough and overwrites memory. |
||||
|
|
||||
|
When this happens the the hypervisor daemon crashes. |
||||
|
|
||||
|
This can be triggered e.g. by passing 1023 and 4198405 as values which |
||||
|
multiply to 1019 after wrapping to 32 bit unsigned value. |
||||
|
|
||||
|
Use the VIR_INT_MULTIPLY_OVERFLOW macro in the check to avoid the issue |
||||
|
the same way as we do for other APIs doing multiplication of arguments |
||||
|
to determine amount of required memory. |
||||
|
|
||||
|
Fixes: 34f2d0319d2098c77c8cc27d8350616029125a2b (v1.2.5-164-g34f2d0319d) |
||||
|
Closes: https://gitlab.com/libvirt/libvirt/-/work_items/903 |
||||
|
Signed-off-by: Peter Krempa <pkrempa@redhat.com> |
||||
|
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com> |
||||
|
(cherry picked from commit 5a62cbf2907d4590283597b46da9c0f41e7b4d4f) |
||||
|
|
||||
|
https://redhat.atlassian.net/browse/RHEL-245281 |
||||
|
---
|
||||
|
src/remote/remote_daemon_dispatch.c | 9 +++++---- |
||||
|
1 file changed, 5 insertions(+), 4 deletions(-) |
||||
|
|
||||
|
diff --git a/src/remote/remote_daemon_dispatch.c b/src/remote/remote_daemon_dispatch.c
|
||||
|
index 7e74ff063f..33b95f05a4 100644
|
||||
|
--- a/src/remote/remote_daemon_dispatch.c
|
||||
|
+++ b/src/remote/remote_daemon_dispatch.c
|
||||
|
@@ -6658,13 +6658,14 @@ remoteDispatchNodeGetFreePages(virNetServer *server G_GNUC_UNUSED,
|
||||
|
if (!conn) |
||||
|
goto cleanup; |
||||
|
|
||||
|
- if (args->pages.pages_len * args->cellCount > REMOTE_NODE_MAX_CELLS) {
|
||||
|
- virReportError(VIR_ERR_INTERNAL_ERROR, "%s",
|
||||
|
- _("the result won't fit into REMOTE_NODE_MAX_CELLS"));
|
||||
|
+ if (VIR_INT_MULTIPLY_OVERFLOW(args->pages.pages_len, args->cellCount) ||
|
||||
|
+ args->pages.pages_len * args->cellCount > REMOTE_NODE_MAX_CELLS) {
|
||||
|
+ virReportError(VIR_ERR_INTERNAL_ERROR,
|
||||
|
+ _("npages * cellcount > REMOTE_NODE_MAX_CELLS (%1$u)"),
|
||||
|
+ REMOTE_NODE_MAX_CELLS);
|
||||
|
goto cleanup; |
||||
|
} |
||||
|
|
||||
|
- /* Allocate return buffer. */
|
||||
|
ret->counts.counts_val = g_new0(uint64_t, |
||||
|
args->pages.pages_len * args->cellCount); |
||||
|
|
||||
|
--
|
||||
|
2.55.0 |
||||
Loading…
Reference in new issue