Commit 007a9c7fce for qemu.org

commit 007a9c7fce1701f7631cc8717cb37434f653825f
Author: Stefan Berger <stefanb@linux.vnet.ibm.com>
Date:   Fri Oct 2 10:25:15 2026 -0400

    hw/tpm: crb: Consider response_buffer->len of received response

    When the CRB receives a TPM reponse from the backend, then reject responses
    that are shorter than the TPM_HEADER_SIZE. When determining the size of the
    reponse, also consider the length of the response_buffer as being possibly
    shorter than the negotiated backend buffer size or the size indicated in
    the response itself.

    Fixes: 2a660ad67d15 ("hw/tpm: Implement TPM CRB chunking logic")
    Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
    Link: https://lore.kernel.org/qemu-devel/20261002142516.2063735-10-stefanb@linux.ibm.com
    Signed-off-by: Stefan Berger <stefanb@linux.ibm.com>

diff --git a/hw/tpm/tpm_crb.c b/hw/tpm/tpm_crb.c
index 5c50a79936..78db220520 100644
--- a/hw/tpm/tpm_crb.c
+++ b/hw/tpm/tpm_crb.c
@@ -323,13 +323,15 @@ static void tpm_crb_request_completed(TPMIf *ti, int ret)
     CRBState *s = CRB(ti);

     ARRAY_FIELD_DP32(s->regs, CRB_CTRL_START, Start, 0);
-    if (ret != 0) {
+    if (ret != 0 || s->response_buffer->len < TPM_HEADER_SIZE) {
         ARRAY_FIELD_DP32(s->regs, CRB_CTRL_STS,
                          tpmSts, 1); /* fatal error */
         tpm_crb_clear_internal_buffers(s);
     } else {
         uint32_t actual_resp_size = tpm_cmd_get_size(s->response_buffer->data);
         uint32_t total_resp_size = MIN(actual_resp_size, s->be_buffer_size);
+
+        total_resp_size = MIN(total_resp_size, s->response_buffer->len);
         g_byte_array_set_size(s->response_buffer, total_resp_size);
         s->response_offset = 0;
     }