diff --git a/meta/recipes-devtools/qemu/qemu.inc b/meta/recipes-devtools/qemu/qemu.inc index f973c0a8d1..73b2f3e607 100644 --- a/meta/recipes-devtools/qemu/qemu.inc +++ b/meta/recipes-devtools/qemu/qemu.inc @@ -50,6 +50,7 @@ SRC_URI = "https://download.qemu.org/${BPN}-${PV}.tar.xz \ file://CVE-2024-6519.patch \ file://CVE-2025-14876_p1.patch \ file://CVE-2025-14876_p2.patch \ + file://CVE-2026-0665.patch \ " UPSTREAM_CHECK_REGEX = "qemu-(?P\d+(\.\d+)+)\.tar" diff --git a/meta/recipes-devtools/qemu/qemu/CVE-2026-0665.patch b/meta/recipes-devtools/qemu/qemu/CVE-2026-0665.patch new file mode 100644 index 0000000000..9264ba38cc --- /dev/null +++ b/meta/recipes-devtools/qemu/qemu/CVE-2026-0665.patch @@ -0,0 +1,38 @@ +From 91e98ce0a879010ef5b5ab5778cc71c0e9e92a57 Mon Sep 17 00:00:00 2001 +From: Vulnerability Report +Date: Fri, 9 Jan 2026 10:35:48 +0800 +Subject: [PATCH] hw/i386/kvm: fix PIRQ bounds check in xen_physdev_map_pirq() + +Reject pirq == s->nr_pirqs in xen_physdev_map_pirq(). + +CVE: CVE-2026-0665 +Upstream-Status: Backport [https://gitlab.com/qemu-project/qemu/-/commit/4ba877461e6b1a8637b15ff1a8c77ba97639c927] + +Fixes: aa98ee38a5 ("hw/xen: Implement emulated PIRQ hypercall support") +Fixes: CVE-2026-0665 +Reported-by: DARKNAVY (@DarkNavyOrg) +Reviewed-by: David Woodhouse +Signed-off-by: Vulnerability Report +Link: https://lore.kernel.org/r/13FE03BE60EA78D6+20260109023548.4047-1-vr@darknavy.com +Signed-off-by: Paolo Bonzini +(cherry picked from commit c7504ba2a560fd884557f6e5142f03b491aad0c7) +Signed-off-by: Michael Tokarev +(cherry picked from commit 4ba877461e6b1a8637b15ff1a8c77ba97639c927) +Signed-off-by: Ashishkumar Parmar +--- + hw/i386/kvm/xen_evtchn.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/hw/i386/kvm/xen_evtchn.c b/hw/i386/kvm/xen_evtchn.c +index 02b8cbf8d..5a1ad3782 100644 +--- a/hw/i386/kvm/xen_evtchn.c ++++ b/hw/i386/kvm/xen_evtchn.c +@@ -1843,7 +1843,7 @@ int xen_physdev_map_pirq(struct physdev_map_pirq *map) + return pirq; + } + map->pirq = pirq; +- } else if (pirq > s->nr_pirqs) { ++ } else if (pirq >= s->nr_pirqs) { + return -EINVAL; + } else { + /*