mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/3] KVM: SEV: only access GHCB fields once
@ 2023-08-04 17:33 Paolo Bonzini
  2023-08-04 17:33 ` [PATCH 1/3] KVM: SEV: snapshot the GHCB before accessing it Paolo Bonzini
                   ` (4 more replies)
  0 siblings, 5 replies; 9+ messages in thread
From: Paolo Bonzini @ 2023-08-04 17:33 UTC (permalink / raw)
  To: linux-kernel, kvm; +Cc: pgonda, seanjc, theflow, vkuznets, thomas.lendacky

The VMGEXIT handler has a time-of-check/time-of-use vulnerability; due
to a double fetch, the guest can exploit a race condition to invoke
the VMGEXIT handler recursively.  It is extremely difficult to
reliably win the race ~100 consecutive times in order to cause an
overflow, and the impact is usually mitigated by CONFIG_VMAP_STACK,
but it ought to be fixed anyway.

One way to do so could be to snapshot the whole GHCB, but this is
relatively expensive.  Instead, because the VMGEXIT handler already
syncs the GHCB to internal KVM state, this series makes sure that the
GHCB is not read outside sev_es_sync_from_ghcb().

Patch 1 adds caching for fields that currently are not snapshotted
in host memory; patch 2 ensures that the cached fields are always used,
thus fixing the race.  Finally patch 3 removes some local variables
that are prone to incorrect use, to avoid reintroducing the race in
other places.

Please review!

Paolo

Paolo Bonzini (3):
  KVM: SEV: snapshot the GHCB before accessing it
  KVM: SEV: only access GHCB fields once
  KVM: SEV: remove ghcb variable declarations

 arch/x86/kvm/svm/sev.c | 124 ++++++++++++++++++++---------------------
 arch/x86/kvm/svm/svm.h |  26 +++++++++
 2 files changed, 87 insertions(+), 63 deletions(-)

-- 
2.39.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2023-08-15 15:53 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-08-04 17:33 [PATCH 0/3] KVM: SEV: only access GHCB fields once Paolo Bonzini
2023-08-04 17:33 ` [PATCH 1/3] KVM: SEV: snapshot the GHCB before accessing it Paolo Bonzini
2023-08-15 15:44   ` Tom Lendacky
2023-08-04 17:33 ` [PATCH 2/3] KVM: SEV: only access GHCB fields once Paolo Bonzini
2023-08-15 15:51   ` Tom Lendacky
2023-08-04 17:33 ` [PATCH 3/3] KVM: SEV: remove ghcb variable declarations Paolo Bonzini
2023-08-15 15:52   ` Tom Lendacky
2023-08-09 14:38 ` [PATCH 0/3] KVM: SEV: only access GHCB fields once Peter Gonda
2023-08-14 12:58 ` Tom Lendacky

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®