From: Viorel Cernateanu via B4 Relay <devnull+vrilutza.gmail.com@kernel.org>
To: Alexander Potapenko <glider@google.com>,
Marco Elver <elver@google.com>,
Dmitry Vyukov <dvyukov@google.com>,
Thomas Gleixner <tglx@kernel.org>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
Andrew Morton <akpm@linux-foundation.org>,
Peter Zijlstra <peterz@infradead.org>,
Kees Cook <kees@kernel.org>
Cc: Borislav Petkov <bp@suse.de>,
kasan-dev@googlegroups.com, linux-kernel@vger.kernel.org,
Viorel Cernateanu <vrilutza@gmail.com>
Subject: [PATCH 1/2] x86/kmsan: Fix CPU entry area metadata lookup
Date: Tue, 06 Oct 2026 21:10:22 +0300 [thread overview]
Message-ID: <20261006-kmsan-serie-v1-1-07fa860ef3de@gmail.com> (raw)
In-Reply-To: <20261006-kmsan-serie-v1-0-07fa860ef3de@gmail.com>
From: Viorel Cernateanu <vrilutza@gmail.com>
arch_kmsan_get_meta_or_null() works out which CPU owns an address in the
CPU entry area as (addr - CPU_ENTRY_AREA_BASE) / CPU_ENTRY_AREA_SIZE.
That is wrong in two ways:
- With KASLR, init_cea_offsets() puts each CPU's area in a random slot,
so the result is a slot number, usually far above NR_CPUS, and
get_cpu_entry_area() reads past the end of __per_cpu_offset[].
- The per-CPU areas start one page higher, at CPU_ENTRY_AREA_PER_CPU.
Even without KASLR, the last page of each area is attributed to the
next CPU, so KMSAN loses that page, and for the last CPU the lookup
uses a CPU that does not exist.
On an Ivy Bridge laptop, a KMSAN kernel with KASLR oopses at boot when
the hard lockup detector sets up its perf event. In QEMU, a module that
reads one byte of the current CPU's GDT alias hits the same bug:
UBSAN: array-index-out-of-bounds in arch/x86/mm/cpu_entry_area.c:25:9
index 2100006 is out of range for type 'unsigned long[64]'
Oops: general protection fault, probably for non-canonical address
RIP: 0010:get_cpu_entry_area+0x14/0x50
Call Trace:
kmsan_get_metadata+0xb2/0x150
kmsan_get_shadow_origin_ptr+0x31/0xa0
__msan_metadata_ptr_for_load_1+0x22/0x40
init_module+0x139/0xff0 [cea_repro]
Find the CPU whose entry area contains the address instead.
Fixes: ce732a7520b0 ("x86: kmsan: handle CPU entry area")
Fixes: 97e3d26b5e5f ("x86/mm: Randomize per-cpu entry area")
Signed-off-by: Viorel Cernateanu <vrilutza@gmail.com>
---
arch/x86/include/asm/kmsan.h | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)
diff --git a/arch/x86/include/asm/kmsan.h b/arch/x86/include/asm/kmsan.h
index d91b37f5b4bb..a71e84d6abab 100644
--- a/arch/x86/include/asm/kmsan.h
+++ b/arch/x86/include/asm/kmsan.h
@@ -13,6 +13,7 @@
#include <asm/cpu_entry_area.h>
#include <asm/processor.h>
+#include <linux/cpumask.h>
#include <linux/mmzone.h>
DECLARE_PER_CPU(char[CPU_ENTRY_AREA_SIZE], cpu_entry_area_shadow);
@@ -32,18 +33,28 @@ static inline void *arch_kmsan_get_meta_or_null(void *addr, bool is_origin)
unsigned long addr64 = (unsigned long)addr;
char *metadata_array;
unsigned long off;
- int cpu;
+ unsigned int cpu;
if ((addr64 < CPU_ENTRY_AREA_BASE) ||
(addr64 >= (CPU_ENTRY_AREA_BASE + CPU_ENTRY_AREA_MAP_SIZE)))
return NULL;
- cpu = (addr64 - CPU_ENTRY_AREA_BASE) / CPU_ENTRY_AREA_SIZE;
- off = addr64 - (unsigned long)get_cpu_entry_area(cpu);
- if ((off < 0) || (off >= CPU_ENTRY_AREA_SIZE))
- return NULL;
- metadata_array = is_origin ? cpu_entry_area_origin :
- cpu_entry_area_shadow;
- return &per_cpu(metadata_array[off], cpu);
+
+ /*
+ * The per-CPU entry areas are not necessarily laid out in CPU order
+ * (see init_cea_offsets()), so find the area containing @addr instead
+ * of computing the CPU from the offset.
+ */
+ for (cpu = 0; cpu < nr_cpu_ids; cpu++) {
+ if (!cpu_possible(cpu))
+ continue;
+ off = addr64 - (unsigned long)get_cpu_entry_area(cpu);
+ if (off >= CPU_ENTRY_AREA_SIZE)
+ continue;
+ metadata_array = is_origin ? cpu_entry_area_origin :
+ cpu_entry_area_shadow;
+ return &per_cpu(metadata_array[off], cpu);
+ }
+ return NULL;
}
/*
--
2.53.0
next prev parent reply other threads:[~2026-10-06 18:10 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 18:10 [PATCH 0/2] x86/kmsan: Fix two bugs in the " Viorel Cernateanu via B4 Relay
2026-10-06 18:10 ` Viorel Cernateanu via B4 Relay [this message]
2026-10-06 18:10 ` [PATCH 2/2] x86/kmsan: Don't call instrumented code from kmsan_virt_addr_valid() Viorel Cernateanu via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006-kmsan-serie-v1-1-07fa860ef3de@gmail.com \
--to=devnull+vrilutza.gmail.com@kernel.org \
--cc=akpm@linux-foundation.org \
--cc=bp@alien8.de \
--cc=bp@suse.de \
--cc=dave.hansen@linux.intel.com \
--cc=dvyukov@google.com \
--cc=elver@google.com \
--cc=glider@google.com \
--cc=hpa@zytor.com \
--cc=kasan-dev@googlegroups.com \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=peterz@infradead.org \
--cc=tglx@kernel.org \
--cc=vrilutza@gmail.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®