usb-host: unchecked bInterfaceNumber causes an out-of-bounds altsetting read
Tooling disclosure: This issue was identified through AI-assisted variant analysis. I manually verified that the supplied PoC works as described, but I have not tested it end-to-end in a full qemu-system-* environment. The PoC was written against an older QEMU commit; however, I confirmed by source inspection that the missing bounds check remains unfixed in the latest QEMU master commit, a759542a2c62f0fd3b65f5a66ad9868201014669 (2026-07-11).
Host environment
- Operating system: Linux (local sanitizer harness; exact distribution not recorded)
- OS/kernel version: N/A for the local harness
- Architecture: x86_64
- QEMU flavor:
qemu-system-x86_64with the libusbusb-hostbackend is affected; the supplied reproduction uses an extracted upstream-function harness - QEMU version: PoC written against
b83371668192a705b878e909c5ae9c1233cbd5fb; the same missing bounds check remains in mastera759542a2c62f0fd3b65f5a66ad9868201014669(2026-07-11)
Emulated/Virtualized environment
- Operating system: Not guest-dependent
- OS/kernel version: Not guest-dependent
- Architecture: Not guest-dependent
Description of problem
The libusb usb-host backend uses the USB-device-controlled bInterfaceNumber as an index into USBDevice.altsetting[USB_MAX_INTERFACES] without checking that it is below USB_MAX_INTERFACES (16). A crafted interface descriptor with bInterfaceNumber = 200 causes a four-byte out-of-bounds read in usb_host_ep_update() at hw/usb/host-libusb.c:896 during host-device attachment.
The supplied AddressSanitizer harness reproduces the out-of-bounds read three out of three times. The demonstrated security consequence is availability loss: the invalid value subsequently reaches an assertion or another altsetting access, although the attached PoC directly proves only the initial out-of-bounds read. The attacker must control a physical USB peripheral attached to a host where the operator has configured QEMU's libusb-backed usb-host passthrough.
Steps to reproduce
INT-usb-qemu-host-libusb-bifnum-oob-read.zip
- Extract the attached report and PoC directory.
- Run
bash ./poc/run.shto clone the pinned QEMU revision, extract the upstream function, and build the sanitizer harness withclang-18. - Observe
AddressSanitizer: heap-buffer-overflow, with a four-byte read inusb_host_ep_update().
Additional information
- Affected file:
hw/usb/host-libusb.c - Affected function:
usb_host_ep_update() - Pinned revision:
b83371668192a705b878e909c5ae9c1233cbd5fb - Attacker-controlled field:
libusb_interface_descriptor.bInterfaceNumber - Missing guard:
intf->bInterfaceNumber < USB_MAX_INTERFACES - The attached
README.mdcontains the complete code-path analysis, impact limitations, proposed fix, and PoC documentation.