usb-host: unchecked bInterfaceNumber causes an out-of-bounds altsetting read

Tooling disclosure: This issue was identified through AI-assisted variant analysis. I manually verified that the supplied PoC works as described, but I have not tested it end-to-end in a full qemu-system-* environment. The PoC was written against an older QEMU commit; however, I confirmed by source inspection that the missing bounds check remains unfixed in the latest QEMU master commit, a759542a2c62f0fd3b65f5a66ad9868201014669 (2026-07-11).

Host environment

  • Operating system: Linux (local sanitizer harness; exact distribution not recorded)
  • OS/kernel version: N/A for the local harness
  • Architecture: x86_64
  • QEMU flavor: qemu-system-x86_64 with the libusb usb-host backend is affected; the supplied reproduction uses an extracted upstream-function harness
  • QEMU version: PoC written against b83371668192a705b878e909c5ae9c1233cbd5fb; the same missing bounds check remains in master a759542a2c62f0fd3b65f5a66ad9868201014669 (2026-07-11)

Emulated/Virtualized environment

  • Operating system: Not guest-dependent
  • OS/kernel version: Not guest-dependent
  • Architecture: Not guest-dependent

Description of problem

The libusb usb-host backend uses the USB-device-controlled bInterfaceNumber as an index into USBDevice.altsetting[USB_MAX_INTERFACES] without checking that it is below USB_MAX_INTERFACES (16). A crafted interface descriptor with bInterfaceNumber = 200 causes a four-byte out-of-bounds read in usb_host_ep_update() at hw/usb/host-libusb.c:896 during host-device attachment.

The supplied AddressSanitizer harness reproduces the out-of-bounds read three out of three times. The demonstrated security consequence is availability loss: the invalid value subsequently reaches an assertion or another altsetting access, although the attached PoC directly proves only the initial out-of-bounds read. The attacker must control a physical USB peripheral attached to a host where the operator has configured QEMU's libusb-backed usb-host passthrough.

Steps to reproduce

INT-usb-qemu-host-libusb-bifnum-oob-read.zip

  1. Extract the attached report and PoC directory.
  2. Run bash ./poc/run.sh to clone the pinned QEMU revision, extract the upstream function, and build the sanitizer harness with clang-18.
  3. Observe AddressSanitizer: heap-buffer-overflow, with a four-byte read in usb_host_ep_update().

Additional information

  • Affected file: hw/usb/host-libusb.c
  • Affected function: usb_host_ep_update()
  • Pinned revision: b83371668192a705b878e909c5ae9c1233cbd5fb
  • Attacker-controlled field: libusb_interface_descriptor.bInterfaceNumber
  • Missing guard: intf->bInterfaceNumber < USB_MAX_INTERFACES
  • The attached README.md contains the complete code-path analysis, impact limitations, proposed fix, and PoC documentation.