s390x/sclpcpi: check event length field before reading from buffer

A guest might send a too short SCCB with SCLP_EVENT_CTRL_PGM_ID. QEMU
would fill its data structures with garbage data. Check for the precise
length of the CBI data structure and reject otherwise.

Fixes: f345978f24 ("hw/s390x: add Control-Program Identification to QOM")
Cc: qemu-stable@nongnu.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Janosch Frank <frankja@linux.ibm.com>
Reviewed-by: Eric Farman <farman@linux.ibm.com>
Message-ID: <20260709142906.197474-3-borntraeger@linux.ibm.com>
Signed-off-by: Cornelia Huck <cohuck@redhat.com>
This commit is contained in:
Christian Borntraeger
2026-07-09 16:29:06 +02:00
committed by Cornelia Huck
parent 20701190e0
commit 8a116a2853

View File

@@ -97,6 +97,11 @@ static int write_event_data(SCLPEvent *event, EventBufferHeader *evt_buf_hdr)
ebh);
SCLPEventCPI *e = SCLP_EVENT_CPI(event);
/* Caller checks sccb length, buffer header checking is our duty */
if (be16_to_cpu(evt_buf_hdr->length) != sizeof(ControlProgramIdMsg)) {
return SCLP_RC_INCONSISTENT_LENGTHS;
}
ascii_put(e->system_type, (char *)cpim->data.system_type,
sizeof(cpim->data.system_type));
ascii_put(e->system_name, (char *)cpim->data.system_name,