From 67ebea439dc91bdf9596ce47c021a19da4507580 Mon Sep 17 00:00:00 2001 From: Peter Maydell Date: Tue, 30 Jun 2026 09:48:55 +0100 Subject: [PATCH] hw/hyperv: Avoid crash if hyperv_find_cpu() passed invalid vp_index MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The hyperv_find_cpu() function finds a CPU from a CPU index; this is basically a wrapper around qemu_get_cpu(). It is allowed to fail, in which case it returns NULL, which its caller handles. However, it includes an assertion check which accidentally assumes the CPU pointer is non-NULL. We could assert only if cs != NULL, but the assertion here is not doing anything interesting -- hyperv_vp_index() is a trivial wrapper returning cs->cpu_index, so this is effectively asserting that qemu_get_cpu() did what it claims to do, i.e. returned us the CPU matching the index we gave it. qemu_get_cpu() is a simple "iterate through list and find matching CPU" which is unlikely to be buggy, and we don't feel the need to sanity-check it in any of our other many uses of it. Drop the assertion entirely. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3568 Signed-off-by: Peter Maydell Acked-by: Maciej S. Szmigiero Reviewed-by: Daniel P. Berrangé Message-ID: <20260630084855.2319838-1-peter.maydell@linaro.org> Signed-off-by: Philippe Mathieu-Daudé --- hw/hyperv/hyperv.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/hw/hyperv/hyperv.c b/hw/hyperv/hyperv.c index 4d90032785..900ff80213 100644 --- a/hw/hyperv/hyperv.c +++ b/hw/hyperv/hyperv.c @@ -237,9 +237,7 @@ struct HvSintRoute { static CPUState *hyperv_find_vcpu(uint32_t vp_index) { - CPUState *cs = qemu_get_cpu(vp_index); - assert(hyperv_vp_index(cs) == vp_index); - return cs; + return qemu_get_cpu(vp_index); } /*