mirror of
https://gitlab.com/qemu-project/qemu.git
synced 2026-08-26 22:23:12 -04:00
ui/vnc: fix OOB write in vnc_refresh_lossy_rect
vnc_refresh_lossy_rect() always marks a full VNC_STAT_RECT (64) rows as dirty when refreshing a lossy tile. When the display height is not a multiple of VNC_STAT_RECT (e.g. VNC_MAX_HEIGHT = 2160), the bottom tile is partial -- the last tile at y=2112 has only 48 valid rows. The unclamped loop writes to vs->dirty[2160..2175], past the end of the VNC_MAX_HEIGHT-sized array. Clamp the row count to the actual surface height so partial bottom tiles only mark valid dirty bitmap entries. Fixes: CVE-2026-48002 Fixes:7d964c9d2f("vnc: refresh lossy rect after a given timeout") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3950 Reported-by: huntr bubble Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com> Signed-off-by: Marc-Andre Lureau <marcandre.lureau@redhat.com> (cherry picked from commit3543c2b855) (Mjt: fixups for missing v10.0.0-2240-g37ff925d5d4 "ui/vnc: Introduce the VncWorker type") Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
This commit is contained in:
parent
980a37f161
commit
5ab666fda9
1 changed files with 9 additions and 1 deletions
10
ui/vnc.c
10
ui/vnc.c
|
|
@ -2988,10 +2988,18 @@ static int vnc_refresh_lossy_rect(VncDisplay *vd, int x, int y)
|
|||
int sty = y / VNC_STAT_RECT;
|
||||
int stx = x / VNC_STAT_RECT;
|
||||
int has_dirty = 0;
|
||||
int height = MIN(pixman_image_get_height(vd->guest.fb),
|
||||
pixman_image_get_height(vd->server));
|
||||
int rows;
|
||||
|
||||
y = QEMU_ALIGN_DOWN(y, VNC_STAT_RECT);
|
||||
x = QEMU_ALIGN_DOWN(x, VNC_STAT_RECT);
|
||||
|
||||
rows = MIN(VNC_STAT_RECT, height - y);
|
||||
if (rows <= 0) {
|
||||
return 0;
|
||||
}
|
||||
|
||||
QTAILQ_FOREACH(vs, &vd->clients, next) {
|
||||
int j;
|
||||
|
||||
|
|
@ -3005,7 +3013,7 @@ static int vnc_refresh_lossy_rect(VncDisplay *vd, int x, int y)
|
|||
}
|
||||
|
||||
vs->lossy_rect[sty][stx] = 0;
|
||||
for (j = 0; j < VNC_STAT_RECT; ++j) {
|
||||
for (j = 0; j < rows; ++j) {
|
||||
bitmap_set(vs->dirty[y + j],
|
||||
x / VNC_DIRTY_PIXELS_PER_BIT,
|
||||
VNC_STAT_RECT / VNC_DIRTY_PIXELS_PER_BIT);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue