{"id":2227391,"url":"http://patchwork.ozlabs.org/api/patches/2227391/?format=json","web_url":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20260423151946.1853943-3-alex.bennee@linaro.org/","project":{"id":14,"url":"http://patchwork.ozlabs.org/api/projects/14/?format=json","name":"QEMU Development","link_name":"qemu-devel","list_id":"qemu-devel.nongnu.org","list_email":"qemu-devel@nongnu.org","web_url":"","scm_url":"","webscm_url":"","list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20260423151946.1853943-3-alex.bennee@linaro.org>","list_archive_url":null,"date":"2026-04-23T15:19:46","name":"[PULL,2/2] hw/display: don't accidentally autofree existing virgl resources","commit_ref":null,"pull_url":null,"state":"new","archived":false,"hash":"91ee99560ab9680fefcf2ce2fe73dd3ec002abc6","submitter":{"id":39532,"url":"http://patchwork.ozlabs.org/api/people/39532/?format=json","name":"Alex Bennée","email":"alex.bennee@linaro.org"},"delegate":null,"mbox":"http://patchwork.ozlabs.org/project/qemu-devel/patch/20260423151946.1853943-3-alex.bennee@linaro.org/mbox/","series":[{"id":501209,"url":"http://patchwork.ozlabs.org/api/series/501209/?format=json","web_url":"http://patchwork.ozlabs.org/project/qemu-devel/list/?series=501209","date":"2026-04-23T15:19:44","name":"[PULL,1/2] ui/sdl2: Fix assumption of EGL presence at runtime","version":1,"mbox":"http://patchwork.ozlabs.org/series/501209/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2227391/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2227391/checks/","tags":{},"related":[],"headers":{"Return-Path":"<qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=linaro.org header.i=@linaro.org header.a=rsa-sha256\n header.s=google header.b=jB9b40NM;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=nongnu.org\n (client-ip=209.51.188.17; helo=lists1p.gnu.org;\n envelope-from=qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org;\n receiver=patchwork.ozlabs.org)"],"Received":["from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17])\n\t(using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits))\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g1ftk0MHHz1y2d\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 24 Apr 2026 01:21:02 +1000 (AEST)","from localhost ([::1] helo=lists1p.gnu.org)\n\tby lists1p.gnu.org with esmtp (Exim 4.90_1)\n\t(envelope-from <qemu-devel-bounces@nongnu.org>)\n\tid 1wFvqQ-0005Ux-QZ; Thu, 23 Apr 2026 11:19:58 -0400","from eggs.gnu.org ([2001:470:142:3::10])\n by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)\n (Exim 4.90_1) (envelope-from <alex.bennee@linaro.org>)\n id 1wFvqP-0005Uf-BC\n for qemu-devel@nongnu.org; Thu, 23 Apr 2026 11:19:57 -0400","from mail-wr1-x42d.google.com ([2a00:1450:4864:20::42d])\n by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128)\n (Exim 4.90_1) (envelope-from <alex.bennee@linaro.org>)\n id 1wFvqN-0002GZ-Qc\n for qemu-devel@nongnu.org; Thu, 23 Apr 2026 11:19:57 -0400","by mail-wr1-x42d.google.com with SMTP id\n ffacd0b85a97d-43cf7683a28so4643203f8f.2\n for <qemu-devel@nongnu.org>; Thu, 23 Apr 2026 08:19:53 -0700 (PDT)","from draig.lan ([185.124.0.195]) by smtp.gmail.com with ESMTPSA id\n ffacd0b85a97d-43fe4cb1249sm50417720f8f.5.2026.04.23.08.19.47\n (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n Thu, 23 Apr 2026 08:19:47 -0700 (PDT)","from draig.lan (localhost [IPv6:::1])\n by draig.lan (Postfix) with ESMTP id CA1F35F943;\n Thu, 23 Apr 2026 16:19:46 +0100 (BST)"],"DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=linaro.org; s=google; t=1776957592; x=1777562392; darn=nongnu.org;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:from:to:cc:subject:date\n :message-id:reply-to;\n bh=228cf+S0c2e/rGab2mnaiBCrE3sra0xAuasuA/jsx9E=;\n b=jB9b40NMRABq2FHd2IJ5iW4QbywGYjsx7jrYPgM76rvzMLHNaP1rfo1jPRpsv7amVt\n KhiI3UBB13geVps2LdhiT2onsq+DvDD0dSnCccsAbGYHEMvBrAo4v7AcUag4+GFXYcwI\n N0yCVhD5cZz/1dFy4CuChC1xdDFi9ycMQuetlvDY6xObVDI+vALtoX8tMEKeprwfLuiY\n sbnyzjzwx0fxco/PwUXGwoXkiq9xjwszJBjcDUtWTIVAcUmhPC1M5pF6q67V7GL+4hUk\n Mz2q3OUmeFZ2N1NcBgYiXdNGE9ypW1SthNUc7J7IdlO1DJMRLARz9CGTRa5atQUEwYdP\n v69Q==","X-Google-DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=1e100.net; s=20251104; t=1776957592; x=1777562392;\n h=content-transfer-encoding:mime-version:references:in-reply-to\n :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from\n :to:cc:subject:date:message-id:reply-to;\n bh=228cf+S0c2e/rGab2mnaiBCrE3sra0xAuasuA/jsx9E=;\n b=NJYoq7cbz+sTFpIzhA9DxL6TNPM3/nuTNiX8pdmu83ycgWqt68tifEO9iNsjnbUl5D\n rMDwQhmlePRycqEf9/xU/FlinNBFe5YxY+xK34HZ53KHNBchKJIGhg0KKbljIIbFWyp2\n taTq4KoZ0bf0DBbdx67oB9wvqSXV8JLOdnD9KPkrkoriYtbChoky5gu3ZGAzdZxM1aOD\n T2NNEWjuUa/nFo4MneGSW25CZ0dwiYk+oKJrhJJ8K3TCjD8VntggkfFV3il4OcA8RGai\n az0BajcvfGFUtfjcMRMBjPhxaDE/4CSgyO9HYIGeVf8WbQTJ3CNO0y2/VOgX/Ij48DI4\n UlHw==","X-Gm-Message-State":"AOJu0YwP8ZS0KxdxMQqcTSPydRbvKBMshsqU7Uv6wrESyoWvyMeq1n6Y\n TYt2GaqSt6V785LXAdbT2ep4wIOVm5pxZfIwGkbRXu8sSB1oGMcp6iWRK21MHa4yI7s=","X-Gm-Gg":"AeBDievrqtBcRiDYKiRXZB/nftk1gAmfvRhrE5qur+sRfNaapngydRPIhyV5IqFUi2w\n Fulc7N3XXDQ4+W4jnyan3wlr4XvOnrXc6hOIOQDiSRLz6OizufGqd3Ez3tVnqkcGipflb/nauQV\n 4B2BAg7bMzaF7S7CrvaGwYRzTeslk84cv6t1zAtXods7wX0THhcYRQnzt8O6yyz8h0jXG06o+/V\n CkFINWMiFaxV9Qctg7befj1d2ldwUz+kE9RMbJlOGpPymgLdkOnmOdZ36USPn/ob2hm9uBsn0Iq\n ivybzTPnj1axgtnVJ/sTV2UmL5aBULXprPdbWC9nseMU/hhDJE9J8uK0eiizjODFgsGy5Vh+fWL\n 3szpvcCjtMYpG2vGXu7GUfd6F9FUndgjJQhQD7z0rtFdO6955aAG6POoDUyN8EEn+4E/FHyvXEV\n cfjE70BoXWOTBUK3YcryEAsOFiDJDtLeckAQ==","X-Received":"by 2002:a5d:64c4:0:b0:43d:708f:a63e with SMTP id\n ffacd0b85a97d-43fe3dbddbbmr41774378f8f.10.1776957592440;\n Thu, 23 Apr 2026 08:19:52 -0700 (PDT)","From":"=?utf-8?q?Alex_Benn=C3=A9e?= <alex.bennee@linaro.org>","To":"qemu-devel@nongnu.org","Cc":"=?utf-8?q?Alex_Benn=C3=A9e?= <alex.bennee@linaro.org>,\n Manos Pitsidianakis <manos.pitsidianakis@linaro.org>, qemu-stable@nongnu.org,\n Dmitry Osipenko <dmitry.osipenko@collabora.com>,\n \"Michael S. Tsirkin\" <mst@redhat.com>,\n Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>","Subject":"[PULL 2/2] hw/display: don't accidentally autofree existing virgl\n resources","Date":"Thu, 23 Apr 2026 16:19:46 +0100","Message-ID":"<20260423151946.1853943-3-alex.bennee@linaro.org>","X-Mailer":"git-send-email 2.47.3","In-Reply-To":"<20260423151946.1853943-1-alex.bennee@linaro.org>","References":"<20260423151946.1853943-1-alex.bennee@linaro.org>","MIME-Version":"1.0","Content-Type":"text/plain; charset=UTF-8","Content-Transfer-Encoding":"8bit","Received-SPF":"pass client-ip=2a00:1450:4864:20::42d;\n envelope-from=alex.bennee@linaro.org; helo=mail-wr1-x42d.google.com","X-Spam_score_int":"-20","X-Spam_score":"-2.1","X-Spam_bar":"--","X-Spam_report":"(-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,\n DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,\n RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,\n SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no","X-Spam_action":"no action","X-BeenThere":"qemu-devel@nongnu.org","X-Mailman-Version":"2.1.29","Precedence":"list","List-Id":"qemu development <qemu-devel.nongnu.org>","List-Unsubscribe":"<https://lists.nongnu.org/mailman/options/qemu-devel>,\n <mailto:qemu-devel-request@nongnu.org?subject=unsubscribe>","List-Archive":"<https://lists.nongnu.org/archive/html/qemu-devel>","List-Post":"<mailto:qemu-devel@nongnu.org>","List-Help":"<mailto:qemu-devel-request@nongnu.org?subject=help>","List-Subscribe":"<https://lists.nongnu.org/mailman/listinfo/qemu-devel>,\n <mailto:qemu-devel-request@nongnu.org?subject=subscribe>","Errors-To":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org","Sender":"qemu-devel-bounces+incoming=patchwork.ozlabs.org@nongnu.org"},"content":"While sanity checking a create blob operation the use of the auto\nfreed res variable could lead to inadvertently freeing an existing\nblob.\n\nAvoid this by in-lining the virtio_gpu_virgl_find_resource() check as\nthe value is not needed anyway.\n\nWhile at it add a comment to the end and use g_steal_pointer to make\nit clearer the object lifetime exceeds the function bounds if we pass\nall the checks.\n\nFixes: CVE-2026-6502\nFixes: 7c092f17cce (virtio-gpu: Handle resource blob commands)\nMessage-ID: 20260417094443.785462-1-alex.bennee@linaro.org\nReviewed-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>\nCc: qemu-stable@nongnu.org\nMessage-ID: <20260417122703.845442-1-alex.bennee@linaro.org>\nSigned-off-by: Alex Bennée <alex.bennee@linaro.org>\nReviewed-by: Dmitry Osipenko <dmitry.osipenko@collabora.com>","diff":"diff --git a/hw/display/virtio-gpu-virgl.c b/hw/display/virtio-gpu-virgl.c\nindex b7a2d160ddd..add85bd4e61 100644\n--- a/hw/display/virtio-gpu-virgl.c\n+++ b/hw/display/virtio-gpu-virgl.c\n@@ -830,8 +830,7 @@ static void virgl_cmd_resource_create_blob(VirtIOGPU *g,\n         return;\n     }\n \n-    res = virtio_gpu_virgl_find_resource(g, cblob.resource_id);\n-    if (res) {\n+    if (virtio_gpu_virgl_find_resource(g, cblob.resource_id)) {\n         qemu_log_mask(LOG_GUEST_ERROR, \"%s: resource already exists %d\\n\",\n                       __func__, cblob.resource_id);\n         cmd->error = VIRTIO_GPU_RESP_ERR_INVALID_RESOURCE_ID;\n@@ -884,8 +883,9 @@ static void virgl_cmd_resource_create_blob(VirtIOGPU *g,\n \n     res->base.dmabuf_fd = info.fd;\n \n+    /* Now live, cleaned up in virtio_gpu_virgl_resource_unref */\n     QTAILQ_INSERT_HEAD(&g->reslist, &res->base, next);\n-    res = NULL;\n+    g_steal_pointer(&res);\n }\n \n static void virgl_cmd_resource_map_blob(VirtIOGPU *g,\n","prefixes":["PULL","2/2"]}