From b378a1bd86b4f25255eada916e34ebd66a3e7437 Mon Sep 17 00:00:00 2001 From: Peter Maydell Date: Mon, 13 Jul 2026 12:34:17 +0100 Subject: [PATCH] hw/display/sm501: Catch bad coordinates for RTL operations The sm501 code doesn't check whether a right-to-left operation has specified a width greater than the x-coordinate (which would make it extend off the left edge of the screen), or similarly a height greater than the y-coordinate. This means the guest can misprogram the device so that we underflow when calculating the address of the top left pixel, which might result in accessing out of bounds memory. Catch this as a guest error and ignore the operation. Reported-by: Yannick Wang Tested-by: BALATON Zoltan Reviewed-by: BALATON Zoltan Signed-off-by: Peter Maydell Message-id: 20260707150933.1410507-2-peter.maydell@linaro.org Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3920 Signed-off-by: Peter Maydell --- hw/display/sm501.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/hw/display/sm501.c b/hw/display/sm501.c index af87004837..0da25477bc 100644 --- a/hw/display/sm501.c +++ b/hw/display/sm501.c @@ -723,6 +723,10 @@ static void sm501_2d_operation(SM501State *s) } if (rtl) { + if (dst_x < (width - 1) || dst_y < (height - 1)) { + qemu_log_mask(LOG_GUEST_ERROR, "sm501: RTL op out of bounds\n"); + return; + } dst_x -= width - 1; dst_y -= height - 1; } @@ -748,6 +752,10 @@ static void sm501_2d_operation(SM501State *s) } if (rtl) { + if (src_x < (width - 1) || src_y < (height - 1)) { + qemu_log_mask(LOG_GUEST_ERROR, "sm501: RTL op out of bounds\n"); + return; + } src_x -= width - 1; src_y -= height - 1; }