Commit 665c854390 for qemu.org

commit 665c854390e0db15ed55b985ca850c36b28b0e57
Author: Michael S. Tsirkin <mst@redhat.com>
Date:   Wed Jul 8 11:38:25 2026 -0400

    virtio: fail early on bad config_len in migration

    virtio_load() attempts to load config_len bytes from the migration
    stream. If that's huge (e.g. 4g) this will uselessly spin
    beyond the end of the stream for seconds. Not nice.
    Check qemu_file_get_error() and bail out early, instead.

    Also note that config_len is int32_t but is coerced to unsigned when
    used. Switch it to uint32_t to make this clearer.

    Fixes: 2f5732e964 ("Allow mismatched virtio config-len")
    Cc: Dr. David Alan Gilbert <dave@treblig.org>
    Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3891
    Reported-by: Feifan Qian <bea1e@proton.me>
    Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
    Message-ID: <cfbefa358af5885eb386637216552bfeba5e7bbc.1784898922.git.mst@redhat.com>
    Reviewed-by: Dr. David Alan Gilbert <dave@treblig.org>

diff --git a/hw/virtio/virtio.c b/hw/virtio/virtio.c
index 2766217ddd..979c4065b7 100644
--- a/hw/virtio/virtio.c
+++ b/hw/virtio/virtio.c
@@ -3505,7 +3505,7 @@ int coroutine_mixed_fn
 virtio_load(VirtIODevice *vdev, QEMUFile *f, int version_id)
 {
     int i, ret;
-    int32_t config_len;
+    uint32_t config_len;
     uint32_t num;
     uint32_t features;
     BusState *qbus = qdev_get_parent_bus(DEVICE(vdev));
@@ -3553,6 +3553,9 @@ virtio_load(VirtIODevice *vdev, QEMUFile *f, int version_id)
     qemu_get_buffer(f, vdev->config, MIN(config_len, vdev->config_len));

     while (config_len > vdev->config_len) {
+        if (qemu_file_get_error(f)) {
+            return -1;
+        }
         qemu_get_byte(f);
         config_len--;
     }