summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorPeter Marko <peter.marko@siemens.com>2025-10-11 23:39:36 +0200
committerSteve Sakoman <steve@sakoman.com>2025-10-24 06:23:39 -0700
commita04f9ab3a5f5d813b581a4dfa19ac21dd6c5ac67 (patch)
tree778c3491adb1e83a0762736f5c1e93954f403cc9
parentf16cffd030d21d12dd57bb95cfc310bda41f8a1f (diff)
downloadpoky-a04f9ab3a5f5d813b581a4dfa19ac21dd6c5ac67.tar.gz
qemu: patch CVE-2024-8354
Pick commit per [1]. [1] https://security-tracker.debian.org/tracker/CVE-2024-8354 (From OE-Core rev: 4bab523ed8ee34e8c09deb631fc82417aa0784b9) Signed-off-by: Peter Marko <peter.marko@siemens.com> Signed-off-by: Steve Sakoman <steve@sakoman.com>
-rw-r--r--meta/recipes-devtools/qemu/qemu.inc1
-rw-r--r--meta/recipes-devtools/qemu/qemu/CVE-2024-8354.patch75
2 files changed, 76 insertions, 0 deletions
diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc
index 220f0a161c..60d372fce0 100644
--- a/meta/recipes-devtools/qemu/qemu.inc
+++ b/meta/recipes-devtools/qemu/qemu.inc
@@ -41,6 +41,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \
41 file://0001-sched_attr-Do-not-define-for-glibc-2.41.patch \ 41 file://0001-sched_attr-Do-not-define-for-glibc-2.41.patch \
42 file://qemu-guest-agent.init \ 42 file://qemu-guest-agent.init \
43 file://qemu-guest-agent.udev \ 43 file://qemu-guest-agent.udev \
44 file://CVE-2024-8354.patch \
44 " 45 "
45UPSTREAM_CHECK_REGEX = "qemu-(?P<pver>\d+(\.\d+)+)\.tar" 46UPSTREAM_CHECK_REGEX = "qemu-(?P<pver>\d+(\.\d+)+)\.tar"
46 47
diff --git a/meta/recipes-devtools/qemu/qemu/CVE-2024-8354.patch b/meta/recipes-devtools/qemu/qemu/CVE-2024-8354.patch
new file mode 100644
index 0000000000..5472efcd09
--- /dev/null
+++ b/meta/recipes-devtools/qemu/qemu/CVE-2024-8354.patch
@@ -0,0 +1,75 @@
1From 746269eaae16423572ae7c0dfeb66140fa882149 Mon Sep 17 00:00:00 2001
2From: Peter Maydell <peter.maydell@linaro.org>
3Date: Mon, 15 Sep 2025 14:29:10 +0100
4Subject: [PATCH] hw/usb/hcd-uhci: don't assert for SETUP to non-0 endpoint
5
6If the guest feeds invalid data to the UHCI controller, we
7can assert:
8qemu-system-x86_64: ../../hw/usb/core.c:744: usb_ep_get: Assertion `pid == USB_TOKEN_IN || pid == USB_TOKEN_OUT' failed.
9
10(see issue 2548 for the repro case). This happens because the guest
11attempts USB_TOKEN_SETUP to an endpoint other than 0, which is not
12valid. The controller code doesn't catch this guest error, so
13instead we hit the assertion in the USB core code.
14
15Catch the case of SETUP to non-zero endpoint, and treat it as a fatal
16error in the TD, in the same way we do for an invalid PID value in
17the TD.
18
19This is the UHCI equivalent of the same bug in OHCI that we fixed in
20commit 3c3c233677 ("hw/usb/hcd-ohci: Fix #1510, #303: pid not IN or
21OUT").
22
23This bug has been tracked as CVE-2024-8354.
24
25Cc: qemu-stable@nongnu.org
26Fixes: https://gitlab.com/qemu-project/qemu/-/issues/2548
27Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
28Reviewed-by: Michael Tokarev <mjt@tls.msk.ru>
29(cherry picked from commit d0af3cd0274e265435170a583c72b9f0a4100dff)
30Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>
31
32CVE: CVE-2024-8354
33Upstream-Status: Backport [https://gitlab.com/qemu-project/qemu/-/commit/746269eaae16423572ae7c0dfeb66140fa882149]
34Signed-off-by: Peter Marko <peter.marko@siemens.com>
35---
36 hw/usb/hcd-uhci.c | 10 ++++++++--
37 1 file changed, 8 insertions(+), 2 deletions(-)
38
39diff --git a/hw/usb/hcd-uhci.c b/hw/usb/hcd-uhci.c
40index 0561a6d801..8f4d6a0f71 100644
41--- a/hw/usb/hcd-uhci.c
42+++ b/hw/usb/hcd-uhci.c
43@@ -722,6 +722,7 @@ static int uhci_handle_td(UHCIState *s, UHCIQueue *q, uint32_t qh_addr,
44 bool spd;
45 bool queuing = (q != NULL);
46 uint8_t pid = td->token & 0xff;
47+ uint8_t ep_id = (td->token >> 15) & 0xf;
48 UHCIAsync *async;
49
50 async = uhci_async_find_td(s, td_addr);
51@@ -765,9 +766,14 @@ static int uhci_handle_td(UHCIState *s, UHCIQueue *q, uint32_t qh_addr,
52
53 switch (pid) {
54 case USB_TOKEN_OUT:
55- case USB_TOKEN_SETUP:
56 case USB_TOKEN_IN:
57 break;
58+ case USB_TOKEN_SETUP:
59+ /* SETUP is only valid to endpoint 0 */
60+ if (ep_id == 0) {
61+ break;
62+ }
63+ /* fallthrough */
64 default:
65 /* invalid pid : frame interrupted */
66 s->status |= UHCI_STS_HCPERR;
67@@ -814,7 +820,7 @@ static int uhci_handle_td(UHCIState *s, UHCIQueue *q, uint32_t qh_addr,
68 return uhci_handle_td_error(s, td, td_addr, USB_RET_NODEV,
69 int_mask);
70 }
71- ep = usb_ep_get(dev, pid, (td->token >> 15) & 0xf);
72+ ep = usb_ep_get(dev, pid, ep_id);
73 q = uhci_queue_new(s, qh_addr, td, ep);
74 }
75 async = uhci_async_alloc(q, td_addr);