mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Greg KH <gregkh@suse.de>
To: linux-kernel@vger.kernel.org, stable@kernel.org, greg@kroah.com
Cc: stable-review@kernel.org, torvalds@linux-foundation.org,
	akpm@linux-foundation.org, alan@lxorguk.ukuu.org.uk,
	avi@redhat.com, mtosatti@redhat.com
Subject: [22/45] KVM: Fix fs/gs reload oops with invalid ldt
Date: Fri, 19 Nov 2010 13:43:02 -0800	[thread overview]
Message-ID: <20101119214411.230948233@clark.site> (raw)
In-Reply-To: <20101119214439.GA26350@kroah.com>

2.6.32-stable review patch.  If anyone has any objections, please let us know.

------------------

From: Avi Kivity <avi@redhat.com>

commit 9581d442b9058d3699b4be568b6e5eae38a41493 upstream

kvm reloads the host's fs and gs blindly, however the underlying segment
descriptors may be invalid due to the user modifying the ldt after loading
them.

Fix by using the safe accessors (loadsegment() and load_gs_index()) instead
of home grown unsafe versions.

This is CVE-2010-3698.

Signed-off-by: Avi Kivity <avi@redhat.com>
Signed-off-by: Marcelo Tosatti <mtosatti@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@suse.de>

---
 arch/x86/include/asm/kvm_host.h |   24 ------------------------
 arch/x86/kvm/svm.c              |   15 ++++++++++-----
 arch/x86/kvm/vmx.c              |   24 +++++++++---------------
 3 files changed, 19 insertions(+), 44 deletions(-)

--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -674,20 +674,6 @@ static inline struct kvm_mmu_page *page_
 	return (struct kvm_mmu_page *)page_private(page);
 }
 
-static inline u16 kvm_read_fs(void)
-{
-	u16 seg;
-	asm("mov %%fs, %0" : "=g"(seg));
-	return seg;
-}
-
-static inline u16 kvm_read_gs(void)
-{
-	u16 seg;
-	asm("mov %%gs, %0" : "=g"(seg));
-	return seg;
-}
-
 static inline u16 kvm_read_ldt(void)
 {
 	u16 ldt;
@@ -695,16 +681,6 @@ static inline u16 kvm_read_ldt(void)
 	return ldt;
 }
 
-static inline void kvm_load_fs(u16 sel)
-{
-	asm("mov %0, %%fs" : : "rm"(sel));
-}
-
-static inline void kvm_load_gs(u16 sel)
-{
-	asm("mov %0, %%gs" : : "rm"(sel));
-}
-
 static inline void kvm_load_ldt(u16 sel)
 {
 	asm("lldt %0" : : "rm"(sel));
--- a/arch/x86/kvm/svm.c
+++ b/arch/x86/kvm/svm.c
@@ -2698,8 +2698,8 @@ static void svm_vcpu_run(struct kvm_vcpu
 	sync_lapic_to_cr8(vcpu);
 
 	save_host_msrs(vcpu);
-	fs_selector = kvm_read_fs();
-	gs_selector = kvm_read_gs();
+	savesegment(fs, fs_selector);
+	savesegment(gs, gs_selector);
 	ldt_selector = kvm_read_ldt();
 	svm->vmcb->save.cr2 = vcpu->arch.cr2;
 	/* required for live migration with NPT */
@@ -2786,10 +2786,15 @@ static void svm_vcpu_run(struct kvm_vcpu
 	vcpu->arch.regs[VCPU_REGS_RSP] = svm->vmcb->save.rsp;
 	vcpu->arch.regs[VCPU_REGS_RIP] = svm->vmcb->save.rip;
 
-	kvm_load_fs(fs_selector);
-	kvm_load_gs(gs_selector);
-	kvm_load_ldt(ldt_selector);
 	load_host_msrs(vcpu);
+	loadsegment(fs, fs_selector);
+#ifdef CONFIG_X86_64
+	load_gs_index(gs_selector);
+	wrmsrl(MSR_KERNEL_GS_BASE, current->thread.gs);
+#else
+	loadsegment(gs, gs_selector);
+#endif
+	kvm_load_ldt(ldt_selector);
 
 	reload_tss(vcpu);
 
--- a/arch/x86/kvm/vmx.c
+++ b/arch/x86/kvm/vmx.c
@@ -629,7 +629,7 @@ static void vmx_save_host_state(struct k
 	 */
 	vmx->host_state.ldt_sel = kvm_read_ldt();
 	vmx->host_state.gs_ldt_reload_needed = vmx->host_state.ldt_sel;
-	vmx->host_state.fs_sel = kvm_read_fs();
+	savesegment(fs, vmx->host_state.fs_sel);
 	if (!(vmx->host_state.fs_sel & 7)) {
 		vmcs_write16(HOST_FS_SELECTOR, vmx->host_state.fs_sel);
 		vmx->host_state.fs_reload_needed = 0;
@@ -637,7 +637,7 @@ static void vmx_save_host_state(struct k
 		vmcs_write16(HOST_FS_SELECTOR, 0);
 		vmx->host_state.fs_reload_needed = 1;
 	}
-	vmx->host_state.gs_sel = kvm_read_gs();
+	savesegment(gs, vmx->host_state.gs_sel);
 	if (!(vmx->host_state.gs_sel & 7))
 		vmcs_write16(HOST_GS_SELECTOR, vmx->host_state.gs_sel);
 	else {
@@ -665,27 +665,21 @@ static void vmx_save_host_state(struct k
 
 static void __vmx_load_host_state(struct vcpu_vmx *vmx)
 {
-	unsigned long flags;
-
 	if (!vmx->host_state.loaded)
 		return;
 
 	++vmx->vcpu.stat.host_state_reload;
 	vmx->host_state.loaded = 0;
 	if (vmx->host_state.fs_reload_needed)
-		kvm_load_fs(vmx->host_state.fs_sel);
+		loadsegment(fs, vmx->host_state.fs_sel);
 	if (vmx->host_state.gs_ldt_reload_needed) {
 		kvm_load_ldt(vmx->host_state.ldt_sel);
-		/*
-		 * If we have to reload gs, we must take care to
-		 * preserve our gs base.
-		 */
-		local_irq_save(flags);
-		kvm_load_gs(vmx->host_state.gs_sel);
 #ifdef CONFIG_X86_64
-		wrmsrl(MSR_GS_BASE, vmcs_readl(HOST_GS_BASE));
+		load_gs_index(vmx->host_state.gs_sel);
+		wrmsrl(MSR_KERNEL_GS_BASE, current->thread.gs);
+#else
+		loadsegment(gs, vmx->host_state.gs_sel);
 #endif
-		local_irq_restore(flags);
 	}
 	reload_tss();
 	save_msrs(vmx->guest_msrs, vmx->save_nmsrs);
@@ -2342,8 +2336,8 @@ static int vmx_vcpu_setup(struct vcpu_vm
 	vmcs_write16(HOST_CS_SELECTOR, __KERNEL_CS);  /* 22.2.4 */
 	vmcs_write16(HOST_DS_SELECTOR, __KERNEL_DS);  /* 22.2.4 */
 	vmcs_write16(HOST_ES_SELECTOR, __KERNEL_DS);  /* 22.2.4 */
-	vmcs_write16(HOST_FS_SELECTOR, kvm_read_fs());    /* 22.2.4 */
-	vmcs_write16(HOST_GS_SELECTOR, kvm_read_gs());    /* 22.2.4 */
+	vmcs_write16(HOST_FS_SELECTOR, 0);            /* 22.2.4 */
+	vmcs_write16(HOST_GS_SELECTOR, 0);            /* 22.2.4 */
 	vmcs_write16(HOST_SS_SELECTOR, __KERNEL_DS);  /* 22.2.4 */
 #ifdef CONFIG_X86_64
 	rdmsrl(MSR_FS_BASE, a);



  parent reply	other threads:[~2010-11-19 21:50 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-11-19 21:44 [00/45] 2.6.32.26-stable review Greg KH
2010-11-19 21:42 ` Greg KH
2010-11-19 21:42 ` [01/45] staging: usbip: Notify usb core of port status changes Greg KH
2010-11-19 21:42 ` [02/45] staging: usbip: Process event flags without delay Greg KH
2010-11-19 21:42 ` [03/45] powerpc/perf: Fix sampling enable for PPC970 Greg KH
2010-11-19 21:42 ` [04/45] pcmcia: synclink_cs: fix information leak to userland Greg KH
2010-11-19 21:42 ` [05/45] sched: Fix string comparison in /proc/sched_features Greg KH
2010-11-19 21:42 ` [06/45] bluetooth: Fix missing NULL check Greg KH
2010-11-19 21:42 ` [07/45] futex: Fix errors in nested key ref-counting Greg KH
2010-11-19 21:42 ` [08/45] mm, x86: Saving vmcore with non-lazy freeing of vmas Greg KH
2010-11-20  2:16   ` [Stable-review] " Ben Hutchings
2010-11-22 17:59     ` Greg KH
2010-11-19 21:42 ` [09/45] x86, cpu: Fix renamed, not-yet-shipping AMD CPUID feature bit Greg KH
2010-11-19 21:42 ` [10/45] x86, kexec: Make sure to stop all CPUs before exiting the kernel Greg KH
2010-11-19 21:42 ` [11/45] x86, olpc: Dont retry EC commands forever Greg KH
2010-11-19 21:42 ` [12/45] x86, mtrr: Assume SYS_CFG[Tom2ForceMemTypeWB] exists on all future AMD CPUs Greg KH
2010-11-19 21:42 ` [13/45] x86, intr-remap: Set redirection hint in the IRTE Greg KH
2010-11-19 21:42 ` [14/45] x86, kdump: Change copy_oldmem_page() to use cached addressing Greg KH
2010-11-19 21:42 ` [15/45] KVM: SVM: Fix wrong intercept masks on 32 bit Greg KH
2010-11-19 21:42 ` [16/45] KVM: MMU: fix direct sps access corrupted Greg KH
2010-11-19 21:42 ` [17/45] KVM: MMU: fix conflict access permissions in direct sp Greg KH
2010-11-19 21:42 ` [18/45] KVM: VMX: Fix host GDT.LIMIT corruption Greg KH
2010-11-19 21:42 ` [19/45] KVM: SVM: Adjust tsc_offset only if tsc_unstable Greg KH
2010-11-19 21:43 ` [20/45] KVM: x86: Fix SVM VMCB reset Greg KH
2010-11-19 21:43 ` [21/45] [PATCH 7/8] KVM: x86: Move TSC reset out of vmcb_init Greg KH
2010-11-19 21:43 ` Greg KH [this message]
2010-11-19 21:43 ` [23/45] pipe: fix failure to return error code on ->confirm() Greg KH
2010-11-19 21:43 ` [24/45] p54usb: fix off-by-one on !CONFIG_PM Greg KH
2010-11-19 21:43 ` [25/45] p54usb: add five more USBIDs Greg KH
2010-11-19 21:43 ` [26/45] drivers/net/wireless/p54/eeprom.c: Return -ENOMEM on memory allocation failure Greg KH
2010-11-19 21:43 ` [27/45] USB: ftdi_sio: Add PID for accesio products Greg KH
2010-11-19 21:43 ` [28/45] USB: add PID for FTDI based OpenDCC hardware Greg KH
2010-11-19 21:43 ` [29/45] USB: ftdi_sio: new VID/PIDs for various Papouch devices Greg KH
2010-11-19 21:43 ` [30/45] USB: ftdi_sio: add device ids for ScienceScope Greg KH
2010-11-19 21:43 ` [31/45] usb: musb: blackfin: call gpio_free() on error path in musb_platform_init() Greg KH
2010-11-19 21:43 ` [32/45] USB: option: Add more ZTE modem USB ids Greg KH
2010-11-19 21:43 ` [33/45] USB: cp210x: Add Renesas RX-Stick device ID Greg KH
2010-11-19 21:43 ` [34/45] USB: cp210x: Add WAGO 750-923 Service Cable " Greg KH
2010-11-19 21:43 ` [35/45] USB: atmel_usba_udc: force vbus_pin at -EINVAL when gpio_request failled Greg KH
2010-11-22  9:08   ` Nicolas Ferre
2010-11-22 21:31     ` Greg KH
2010-11-19 21:43 ` [36/45] USB: disable endpoints after unbinding interfaces, not before Greg KH
2010-11-19 21:43 ` [37/45] USB: opticon: Fix long-standing bugs in opticon driver Greg KH
2010-11-19 21:43 ` [38/45] USB: accept some invalid ep0-maxpacket values Greg KH
2010-11-19 21:43 ` [39/45] OHCI: work around for nVidia shutdown problem Greg KH
2010-11-20  2:52   ` [Stable-review] " Ben Hutchings
2010-11-20 16:51     ` Alan Stern
2010-11-22 17:55       ` Greg KH
2010-11-22 18:09         ` Alan Stern
2011-01-19 16:51         ` Alan Stern
2011-02-16 21:40           ` [stable] " Greg KH
2011-03-28 16:13   ` Andre "Osku" Schmidt
2010-11-19 21:43 ` [40/45] [SCSI] sd name space exhaustion causes system hang Greg KH
2010-11-19 21:43 ` [41/45] [SCSI] libsas: fix NCQ mixing with non-NCQ Greg KH
2010-11-19 21:43 ` [42/45] [SCSI] gdth: integer overflow in ioctl Greg KH
2010-11-19 21:43 ` [43/45] [SCSI] Fix race when removing SCSI devices Greg KH
2010-11-19 21:43 ` [44/45] [SCSI] Fix regressions in scsi_internal_device_block Greg KH
2010-11-19 21:43 ` [45/45] sgi-xp: incoming XPC channel messages can come in after the channels partition structures have been torn down Greg KH

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20101119214411.230948233@clark.site \
    --to=gregkh@suse.de \
    --cc=akpm@linux-foundation.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=avi@redhat.com \
    --cc=greg@kroah.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mtosatti@redhat.com \
    --cc=stable-review@kernel.org \
    --cc=stable@kernel.org \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome