Commit 1c4908f613 for qemu.org

commit 1c4908f61367f5989143d7746f29ea07f8e02189
Author: Stefan Berger <stefanb@linux.vnet.ibm.com>
Date:   Fri Oct 2 10:25:13 2026 -0400

    hw/tpm: crb: Avoid potential integer underflow

    Avoid a potential integer underflow in tpm_crb_fill_command_response
    that could occur if s->response_offset > s->response_buffer->len and
    the function's call sites were to change.

    tpm_crb_fill_command_response currently has 3 callers that either test
    that 's->response_offset < s->response_buffer->len' is true or ensure that
    s->response_offset = 0 and s->response_buffer->len >= 0. Therefore, the
    integer underflow cannot currently occur. In the worst case the subtraction
    would lead to a '0'.

    Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
    Link: https://lore.kernel.org/qemu-devel/20261002142516.2063735-8-stefanb@linux.ibm.com
    Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>

diff --git a/hw/tpm/tpm_crb.c b/hw/tpm/tpm_crb.c
index daf451aa56..cd46b2e888 100644
--- a/hw/tpm/tpm_crb.c
+++ b/hw/tpm/tpm_crb.c
@@ -180,10 +180,17 @@ static void tpm_crb_fill_command_response(CRBState *s)
      * to the linux guest in chunks by writing it back to MMIO region.
      */
     void *mem = memory_region_get_ram_ptr(&s->cmdmem);
-    uint32_t remaining = s->response_buffer->len - s->response_offset;
-    uint32_t to_copy = MIN(CRB_CTRL_CMD_SIZE, remaining);
+    uint32_t remaining = 0;
+    uint32_t to_copy;

-    memcpy(mem, s->response_buffer->data + s->response_offset, to_copy);
+    if (s->response_offset < s->response_buffer->len) {
+        remaining = s->response_buffer->len - s->response_offset;
+    }
+    to_copy = MIN(CRB_CTRL_CMD_SIZE, remaining);
+
+    if (to_copy) {
+        memcpy(mem, s->response_buffer->data + s->response_offset, to_copy);
+    }

     if (to_copy < CRB_CTRL_CMD_SIZE) {
         memset((guint8 *)mem + to_copy, 0, CRB_CTRL_CMD_SIZE - to_copy);