From 8a116a28535c34b001e68b52f85d6be3acb75350 Mon Sep 17 00:00:00 2001 From: Christian Borntraeger Date: Thu, 9 Jul 2026 16:29:06 +0200 Subject: [PATCH] s390x/sclpcpi: check event length field before reading from buffer A guest might send a too short SCCB with SCLP_EVENT_CTRL_PGM_ID. QEMU would fill its data structures with garbage data. Check for the precise length of the CBI data structure and reject otherwise. Fixes: f345978f24be ("hw/s390x: add Control-Program Identification to QOM") Cc: qemu-stable@nongnu.org Signed-off-by: Christian Borntraeger Reviewed-by: Matthew Rosato Reviewed-by: Janosch Frank Reviewed-by: Eric Farman Message-ID: <20260709142906.197474-3-borntraeger@linux.ibm.com> Signed-off-by: Cornelia Huck --- hw/s390x/sclpcpi.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/hw/s390x/sclpcpi.c b/hw/s390x/sclpcpi.c index 68fc1b809b..ec4bdf2350 100644 --- a/hw/s390x/sclpcpi.c +++ b/hw/s390x/sclpcpi.c @@ -97,6 +97,11 @@ static int write_event_data(SCLPEvent *event, EventBufferHeader *evt_buf_hdr) ebh); SCLPEventCPI *e = SCLP_EVENT_CPI(event); + /* Caller checks sccb length, buffer header checking is our duty */ + if (be16_to_cpu(evt_buf_hdr->length) != sizeof(ControlProgramIdMsg)) { + return SCLP_RC_INCONSISTENT_LENGTHS; + } + ascii_put(e->system_type, (char *)cpim->data.system_type, sizeof(cpim->data.system_type)); ascii_put(e->system_name, (char *)cpim->data.system_name,