From: Paolo Bonzini <pbonzini@redhat.com>
To: linux-kernel@vger.kernel.org, kvm@vger.kernel.org
Cc: pgonda@google.com, seanjc@google.com, theflow@google.com,
vkuznets@redhat.com, thomas.lendacky@amd.com
Subject: [PATCH 0/3] KVM: SEV: only access GHCB fields once
Date: Fri, 4 Aug 2023 13:33:52 -0400 [thread overview]
Message-ID: <20230804173355.51753-1-pbonzini@redhat.com> (raw)
The VMGEXIT handler has a time-of-check/time-of-use vulnerability; due
to a double fetch, the guest can exploit a race condition to invoke
the VMGEXIT handler recursively. It is extremely difficult to
reliably win the race ~100 consecutive times in order to cause an
overflow, and the impact is usually mitigated by CONFIG_VMAP_STACK,
but it ought to be fixed anyway.
One way to do so could be to snapshot the whole GHCB, but this is
relatively expensive. Instead, because the VMGEXIT handler already
syncs the GHCB to internal KVM state, this series makes sure that the
GHCB is not read outside sev_es_sync_from_ghcb().
Patch 1 adds caching for fields that currently are not snapshotted
in host memory; patch 2 ensures that the cached fields are always used,
thus fixing the race. Finally patch 3 removes some local variables
that are prone to incorrect use, to avoid reintroducing the race in
other places.
Please review!
Paolo
Paolo Bonzini (3):
KVM: SEV: snapshot the GHCB before accessing it
KVM: SEV: only access GHCB fields once
KVM: SEV: remove ghcb variable declarations
arch/x86/kvm/svm/sev.c | 124 ++++++++++++++++++++---------------------
arch/x86/kvm/svm/svm.h | 26 +++++++++
2 files changed, 87 insertions(+), 63 deletions(-)
--
2.39.0
next reply other threads:[~2023-08-04 17:34 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-08-04 17:33 Paolo Bonzini [this message]
2023-08-04 17:33 ` [PATCH 1/3] KVM: SEV: snapshot the GHCB before accessing it Paolo Bonzini
2023-08-15 15:44 ` Tom Lendacky
2023-08-04 17:33 ` [PATCH 2/3] KVM: SEV: only access GHCB fields once Paolo Bonzini
2023-08-15 15:51 ` Tom Lendacky
2023-08-04 17:33 ` [PATCH 3/3] KVM: SEV: remove ghcb variable declarations Paolo Bonzini
2023-08-15 15:52 ` Tom Lendacky
2023-08-09 14:38 ` [PATCH 0/3] KVM: SEV: only access GHCB fields once Peter Gonda
2023-08-14 12:58 ` Tom Lendacky
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230804173355.51753-1-pbonzini@redhat.com \
--to=pbonzini@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pgonda@google.com \
--cc=seanjc@google.com \
--cc=theflow@google.com \
--cc=thomas.lendacky@amd.com \
--cc=vkuznets@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®