hw/display/sm501: Catch bad coordinates for RTL operations

The sm501 code doesn't check whether a right-to-left operation has
specified a width greater than the x-coordinate (which would make it
extend off the left edge of the screen), or similarly a height
greater than the y-coordinate.  This means the guest can misprogram
the device so that we underflow when calculating the address of the
top left pixel, which might result in accessing out of bounds
memory.  Catch this as a guest error and ignore the operation.

Reported-by: Yannick Wang
Tested-by: BALATON Zoltan <balaton@eik.bme.hu>
Reviewed-by: BALATON Zoltan <balaton@eik.bme.hu>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Message-id: 20260707150933.1410507-2-peter.maydell@linaro.org
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3920
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
This commit is contained in:
Peter Maydell
2026-07-13 12:34:17 +01:00
parent 2c6fae7d7d
commit b378a1bd86

View File

@@ -723,6 +723,10 @@ static void sm501_2d_operation(SM501State *s)
}
if (rtl) {
if (dst_x < (width - 1) || dst_y < (height - 1)) {
qemu_log_mask(LOG_GUEST_ERROR, "sm501: RTL op out of bounds\n");
return;
}
dst_x -= width - 1;
dst_y -= height - 1;
}
@@ -748,6 +752,10 @@ static void sm501_2d_operation(SM501State *s)
}
if (rtl) {
if (src_x < (width - 1) || src_y < (height - 1)) {
qemu_log_mask(LOG_GUEST_ERROR, "sm501: RTL op out of bounds\n");
return;
}
src_x -= width - 1;
src_y -= height - 1;
}