freenode
Databases & Infrastructure

QEMU patches remaining VGA out-of-bounds writes with virtio-gpu

Stale geometry cache left blank and graphic draw paths writing past undersized shared console surfaces.

QEMU has fixed CVE-2026-97889, a pair of out-of-bounds write bugs in the VGA display path that could fire when virtio-vga’s two renderers share one console surface.

virtio-vga combines classic VGA drawing with virtio-gpu on a single QemuConsole and has no invalidation handshake between them. When virtio-gpu replaces the surface on scanout change, or clears it on reset, the VGA side keeps cached width, height, and depth values. A prior fix closed the text-mode path (CVE-2026-77913). The blank and graphic draw routines still trusted that cache against whatever surface was actually attached.

Blanking used the cached size to fill memory, so a smaller replacement surface (for example a 16×16 placeholder after reset, or after a text-to-graphics switch) let the fill run past the buffer. Graphic mode decided whether to recreate the surface from VGA register state alone; if virtio-gpu had installed a smaller surface, the check saw no change and the draw loop still emitted a full VGA-sized frame into the undersized buffer.

Marc-André Lureau’s fix bounds the blank fill to the live surface dimensions and makes the graphic path re-check surface size so a mismatched foreign surface forces a resize before drawing. He noted that a proper console-level invalidation callback between the two renderers would be cleaner, but the defensive checks are still required against any path that swaps the surface. David Korczynski reported the issue.