Skip to content

Commit

Permalink
Merge tag 'kvm-x86-fixes-6.10-11' of https://github.com/kvm-x86/linux
Browse files Browse the repository at this point in the history
…into HEAD

KVM Xen:

Fix a bug where KVM fails to check the validity of an incoming userspace
virtual address and tries to activate a gfn_to_pfn_cache with a kernel address.
  • Loading branch information
bonzini committed Jul 16, 2024
2 parents 1c5a0b5 + ebbdf37 commit f4501e8
Show file tree
Hide file tree
Showing 2 changed files with 4 additions and 1 deletion.
2 changes: 1 addition & 1 deletion arch/x86/kvm/xen.c
Original file line number Diff line number Diff line change
Expand Up @@ -741,7 +741,7 @@ int kvm_xen_hvm_set_attr(struct kvm *kvm, struct kvm_xen_hvm_attr *data)
} else {
void __user * hva = u64_to_user_ptr(data->u.shared_info.hva);

if (!PAGE_ALIGNED(hva) || !access_ok(hva, PAGE_SIZE)) {
if (!PAGE_ALIGNED(hva)) {
r = -EINVAL;
} else if (!hva) {
kvm_gpc_deactivate(&kvm->arch.xen.shinfo_cache);
Expand Down
3 changes: 3 additions & 0 deletions virt/kvm/pfncache.c
Original file line number Diff line number Diff line change
Expand Up @@ -430,6 +430,9 @@ int kvm_gpc_activate(struct gfn_to_pfn_cache *gpc, gpa_t gpa, unsigned long len)

int kvm_gpc_activate_hva(struct gfn_to_pfn_cache *gpc, unsigned long uhva, unsigned long len)
{
if (!access_ok((void __user *)uhva, len))
return -EINVAL;

return __kvm_gpc_activate(gpc, INVALID_GPA, uhva, len);
}

Expand Down

0 comments on commit f4501e8

Please sign in to comment.