** Description changed:

+ [ Impact ]                                                                    
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+  * Several s390x-specific QEMU device/interface emulation paths (stsi,        
                                                                                
                                                                        
+    sclp write-event-data, PCI BAR region detection, PCI RPCIT ranges,         
                                                                                
                                                                        
+    ioinst/SEI CHSC handler, css CHPID description) do not validate            
                                                                                
                                                                        
+    guest-supplied data strongly enough. A malicious or buggy s390x            
                                                                                
                                                                        
+    guest can trigger out-of-bounds access, hangs or crashes of the            
                                                                                
                                                                        
+    host QEMU process.                                                         
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+  * The fix is a set of 9 hardening cherry-picks (bounds/length                
                                                                                
                                                                        
+    checks) already merged upstream and released in the current                
                                                                                
                                                                        
+    development release (Stonking QEMU 11.0.3) for both qemu and qemu-hwe.     
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+ [ Test Plan ]                                                                 
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+  * Several interfaces have been hardened. For each hardened interface,        
                                                                                
                                                                        
+    exercise it with out-of-range/invalid values from the guest and            
                                                                                
                                                                        
+    confirm QEMU rejects them gracefully instead of crashing/hanging:          
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+    s390x/pci + s390x/ioinst:                                                  
                                                                                
                                                                        
+    General PCI passthrough regression incl unplug/hotplug will cover these 
patches.                                                                        
                                                                           
+                                                                               
                                                                                
                                                                        
+    s390x/sclpcpi + s390x/kvm + s390x/sclp:                                    
                                                                                
                                                                        
+    sclpcpi write, stsi code and both sclp fixes will be driven as part of 
starting s390x kvm guest.                                                       
                                                                            
+                                                                               
                                                                                
                                                                        
+    s390x/css:                                                                 
                                                                                
                                                                        
+    The chpid fix will be driven by starting an s390x kvm guest. The CCW code 
itself will                                                                     
                                                                         
+    also be driven here, but the TIC path within it that is addressed by this 
fix cannot                                                                      
                                                                         
+    be guaranteed to be executed without some manual testing.                  
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+ [ Where problems could occur ]                                                
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+  * The changes touch s390x-only code paths (kvm stsi, sclp, s390x PCI         
                                                                                
                                                                        
+    BAR/RPCIT handling, ioinst/CHSC SEI, css CHPID description), so            
                                                                                
                                                                        
+    regressions are confined to s390x guests/hosts; other                      
                                                                                
                                                                        
+    architectures are not affected.                                            
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+  * Overly strict bounds/length checks could reject requests from              
                                                                                
                                                                        
+    legitimate, well-behaved guests if the accepted ranges are not             
                                                                                
                                                                        
+    exactly matched to spec, potentially breaking PCI passthrough,             
                                                                                
                                                                        
+    DMA/IOMMU windows (RPCIT), channel-subsystem enumeration, or               
                                                                                
                                                                        
+    dynamic I/O configuration (CHSC SEI) for valid workloads.                  
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+  * Because these paths are exercised during device hot-plug, PCI              
                                                                                
                                                                        
+    passthrough and live migration, any subtle behavioural change could        
                                                                                
                                                                        
+    surface as migration incompatibility between hosts running old vs.         
                                                                                
                                                                        
+    patched QEMU, or as functional regressions in those specific               
                                                                                
                                                                        
+    features rather than a full crash.                                         
                                                                                
                                                                        
+                                                                               
                                                                                
                                                                        
+ [ Other Info ]   
+ 
  == Created by <[email protected]> - 2026-07-06 09:40:45 ==
- Several qemu interfaces are not hardened against broken guest usage and might 
result in crashes. 
+ Several qemu interfaces are not hardened against broken guest usage and might 
result in crashes.
  Fix thoses.
  
  Fixes already upstream:
  ------------------------
  
https://gitlab.com/qemu-project/qemu/-/commit/a57e4612b61da20ddab196502c76b4dc05da1de8
  s390x/kvm: clamp stsi 3.2.2 size
- 
  
  Fixes on the mailing list:
  --------------------------
  s390x/sclp: reject invalid write event data headers
  s390x/pci: Tighten region detection for BAR read/write
  s390x/pci: Shrink RPCIT ranges to registered window
  s390x/ioinst: Require strict length and format for SEI CHSC handler
  s390x/css: limit number of CHPIDs in description
  
  https://lore.kernel.org/qemu-
  devel/[email protected]/T/
  
  == Comment: #1 - <[email protected]> - 2026-07-06 09:41:22 ==
  As soon as upstream review is finished. those fixes should be considered for 
all ubuntu releases in service as they allow a guest to trigger host QEMU 
crashes/hangs.
  
  == Comment: #2 - <[email protected]> - 2026-07-07 03:15:47 ==
  New version of patches
  
https://lore.kernel.org/qemu-devel/[email protected]/T/#r57123ee05c7718485f7292839448e6ec54b4b400

** Changed in: qemu (Ubuntu Resolute)
       Status: Incomplete => In Progress

** Changed in: qemu-hwe (Ubuntu Resolute)
       Status: Incomplete => In Progress

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160034

Title:
  [Ubuntu 26.04] qemu s390x: interface hardening fixes

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-z-systems/+bug/2160034/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to