Commit 4f50d637e2 for qemu.org

commit 4f50d637e23770872a997ed2de0729fbacc2c002
Author: Doug Cook <dcook@microsoft.com>
Date:   Mon Aug 17 19:09:06 2026 +0000

    hw/arm/ax3000-soc: fix heap overflow from missing class_size

    TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and
    ax3000_class_init() writes to it:

        Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc);
        sc->num_cpus = AX3000_NUM_CPUS;

    but its TypeInfo omits .class_size, so type_initialize() only allocates
    class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass).
    The store to sc->num_cpus therefore writes 4 bytes of the value 4 just
    past the end of the class allocation, corrupting whatever heap block
    follows it.

    Fix by setting class_size.

    Fixes: 33a71a68c6e1 ("hw/arm: Add Axiado SoC AX3000")
    Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197
    Signed-off-by: Doug Cook <dcook@microsoft.com>
    Message-id: LVXPR21MB70090B04FF7397B0F2A201C8ADA72@LVXPR21MB7009.namprd21.prod.outlook.com
    Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
    Signed-off-by: Peter Maydell <peter.maydell@linaro.org>

diff --git a/hw/arm/ax3000-soc.c b/hw/arm/ax3000-soc.c
index 71e31c6fb4..ebe174fb97 100644
--- a/hw/arm/ax3000-soc.c
+++ b/hw/arm/ax3000-soc.c
@@ -236,6 +236,7 @@ static const TypeInfo axiado_soc_types[] = {
         .instance_size  = sizeof(Ax3000SoCState),
         .instance_init  = ax3000_init,
         .class_init     = ax3000_class_init,
+        .class_size     = sizeof(Ax3000SoCClass),
     }
 };