** Description changed:
+ [ Impact ]
+
+ * Several s390x-specific QEMU device/interface emulation paths (stsi,
+ sclp write-event-data, PCI BAR region detection, PCI RPCIT ranges,
+ ioinst/SEI CHSC handler, css CHPID description) do not validate
+ guest-supplied data strongly enough. A malicious or buggy s390x
+ guest can trigger out-of-bounds access, hangs or crashes of the
+ host QEMU process.
+
+ * The fix is a set of 9 hardening cherry-picks (bounds/length
+ checks) already merged upstream and released in the current
+ development release (Stonking QEMU 11.0.3) for both qemu and qemu-hwe.
+
+ [ Test Plan ]
+
+ * Several interfaces have been hardened. For each hardened interface,
+ exercise it with out-of-range/invalid values from the guest and
+ confirm QEMU rejects them gracefully instead of crashing/hanging:
+
+ s390x/pci + s390x/ioinst:
+ General PCI passthrough regression incl unplug/hotplug will cover these
patches.
+
+ s390x/sclpcpi + s390x/kvm + s390x/sclp:
+ sclpcpi write, stsi code and both sclp fixes will be driven as part of
starting s390x kvm guest.
+
+ s390x/css:
+ The chpid fix will be driven by starting an s390x kvm guest. The CCW code
itself will
+ also be driven here, but the TIC path within it that is addressed by this
fix cannot
+ be guaranteed to be executed without some manual testing.
+
+ [ Where problems could occur ]
+
+ * The changes touch s390x-only code paths (kvm stsi, sclp, s390x PCI
+ BAR/RPCIT handling, ioinst/CHSC SEI, css CHPID description), so
+ regressions are confined to s390x guests/hosts; other
+ architectures are not affected.
+
+ * Overly strict bounds/length checks could reject requests from
+ legitimate, well-behaved guests if the accepted ranges are not
+ exactly matched to spec, potentially breaking PCI passthrough,
+ DMA/IOMMU windows (RPCIT), channel-subsystem enumeration, or
+ dynamic I/O configuration (CHSC SEI) for valid workloads.
+
+ * Because these paths are exercised during device hot-plug, PCI
+ passthrough and live migration, any subtle behavioural change could
+ surface as migration incompatibility between hosts running old vs.
+ patched QEMU, or as functional regressions in those specific
+ features rather than a full crash.
+
+ [ Other Info ]
+
== Created by <[email protected]> - 2026-07-06 09:40:45 ==
- Several qemu interfaces are not hardened against broken guest usage and might
result in crashes.
+ Several qemu interfaces are not hardened against broken guest usage and might
result in crashes.
Fix thoses.
Fixes already upstream:
------------------------
https://gitlab.com/qemu-project/qemu/-/commit/a57e4612b61da20ddab196502c76b4dc05da1de8
s390x/kvm: clamp stsi 3.2.2 size
-
Fixes on the mailing list:
--------------------------
s390x/sclp: reject invalid write event data headers
s390x/pci: Tighten region detection for BAR read/write
s390x/pci: Shrink RPCIT ranges to registered window
s390x/ioinst: Require strict length and format for SEI CHSC handler
s390x/css: limit number of CHPIDs in description
https://lore.kernel.org/qemu-
devel/[email protected]/T/
== Comment: #1 - <[email protected]> - 2026-07-06 09:41:22 ==
As soon as upstream review is finished. those fixes should be considered for
all ubuntu releases in service as they allow a guest to trigger host QEMU
crashes/hangs.
== Comment: #2 - <[email protected]> - 2026-07-07 03:15:47 ==
New version of patches
https://lore.kernel.org/qemu-devel/[email protected]/T/#r57123ee05c7718485f7292839448e6ec54b4b400
** Changed in: qemu (Ubuntu Resolute)
Status: Incomplete => In Progress
** Changed in: qemu-hwe (Ubuntu Resolute)
Status: Incomplete => In Progress
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160034
Title:
[Ubuntu 26.04] qemu s390x: interface hardening fixes
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-z-systems/+bug/2160034/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
