From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2357347D440 for ; Thu, 13 Aug 2026 13:45:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786628722; cv=none; b=hH6O82lVzOwBTP+aWbwYPiz71/X3dCCaGTftXRqLURSfcDvq9rJMWQx4elFKMu0tkvW34xPhBwzk9tGsrfloiunS8hc79Zjwq8Fz2UH8U3kMmhihEzx6Mq6NhYd56fAxoCV2OlX/I5VsZ8WWni6/WGjwktwJCmFpvMRjs/0TPkM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786628722; c=relaxed/simple; bh=NBWxDMgX1ntQ8itk3D8CiEXlI/bvH+OxmmfTTWKn8Mc=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=osiMeip7nmot0E0+g+wLNmCi6Su/eREs6c7GimLjHKQvlxptObErr5mGxFmmbk7vOivwQTj6AtEwTinpdML4UwGFJGs4Ft3byn9OBFkCVxktC9haWs4LexM5IfRtNNxUn9+0Jpm8623nOKLwvoOxPt6wJ4zdsl6PSzq0XUhKgDM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Bq2Pb4MJ; arc=none smtp.client-ip=209.85.210.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Bq2Pb4MJ" Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-84e04598adeso1883017b3a.2 for ; Thu, 13 Aug 2026 06:45:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786628720; x=1787233520; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Fl6HuvcqJhrZa9ThhaR07J0ykt0HktDxO4pMG4WTz+A=; b=Bq2Pb4MJUuc/f6ON76Sk+UykEDGCaxmAs6yMz/X5aY1WcU43HNj6iJEgdo4IqbM+QK EK9XG5tP2wcaP+xRALKpqq4NeoeiQR6j5r1cf4aZkUREvGFrxjVzL4BEDq72/pnO31B6 WukFMckau5mS7DiSWWzld6+05Szc4MXAl4WvUmtfX8CCBga+sctMK4X2bYA6euLYm8BX nyWNCUTQtV1MWxySfEs3OAPMqcrX+Sx1wIaNFbOKw2e1ta/F3LGOn540qWd9uJT3cLfu TgeyBe+LeFcC096Pqi1s1vh4aQwGRbOT0Af7vcnUUzt05OViA0hLF+jklualVnKpMp6U VxoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786628720; x=1787233520; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Fl6HuvcqJhrZa9ThhaR07J0ykt0HktDxO4pMG4WTz+A=; b=l7VJrw32eVlchA8PNVMIIwI0vN9IlGGI8dAiJSyrceTw+ZJUzRHtBUBsvDwSC9uePv AnBkYdgb+DTyjbR2xF5D95pbtyhXadNeZBM0S30P1hjGJQF7mMGteUe+oHU5g6s5dEuQ QW4pWhZm1rsLo655UGK7fU9cE8xZa4J76cFba9UuNX71uZhTSXfixsRezgUNQwHG55q8 1gUZba0DnctTB7YpOkixNJKSG2jFfaaVwUj4SPK66s/KjX7VdrWSbTpjcJj/sVehVJcR /wDBlQWRAX9VqA77SoxiItBGGtcpBrXpXXwnfYiUJuVYd6daesQGyo4JbebfEZ5w8wys oltQ== X-Forwarded-Encrypted: i=1; AHgh+Rr6j1CkLUw4GmihdAUlbKC8dYw+YL8MNqGsSbZw9qD0rpS1c+szAUpVgkOk8F7RqKuuWzHEGk0LgwaYEhg=@vger.kernel.org X-Gm-Message-State: AOJu0YyDaXy1ijWeAiGYWltS7zEC91xuHTyPZdevRV3Ef6G8NpBCHbLH nuadsVgdT9hTnDUwjPHVExYvIF2aP9cr4BDbALo8pPHgkz+TCMQT/QQ1nOhk8Bn+ozh7aFxYMsw 4jX9STg== X-Received: from pfblb8.prod.google.com ([2002:a05:6a00:4f08:b0:845:4da8:56a5]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:6c8a:b0:848:8445:6956 with SMTP id d2e1a72fcca58-84fc6e03a04mr6167423b3a.18.1786628720300; Thu, 13 Aug 2026 06:45:20 -0700 (PDT) Date: Thu, 13 Aug 2026 06:45:18 -0700 In-Reply-To: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260813043932.3214460-1-rkskek9254@gmail.com> <20260813045727.903981F000E9@smtp.kernel.org> Message-ID: Subject: Re: [PATCH] KVM: nVMX: Re-arm the vmcs12 pages request if mapping the pages fails From: Sean Christopherson To: Jinwoo Lee Cc: sashiko-reviews@lists.linux.dev, pbonzini@redhat.com, kvm@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Content-Type: text/plain; charset="us-ascii" On Thu, Aug 13, 2026, Jinwoo Lee wrote: > However, I do not currently see evidence that the SVM failures have the > same unpinned-HPA/UAF mechanism as the nVMX APIC-backed VMCS02 fields. Eh, doesn't really matter. It's still ugly/flawed code that we should fix, especially since fixing this in a common location should be a net reduction in code. > In particular, nested_vmcb02_prepare_control() initially copies > vmcb01's KVM-owned MSRPM address into vmcb02, and > nested_svm_merge_msrpm() switches vmcb02 to the KVM-owned merged MSRPM > only after the merge completes successfully. Losing the request after > a failed merge can therefore allow L2 to run without L1's complete MSR > intercept state, but it does not appear to leave hardware pointing at an > unpinned guest page. I will describe and test the SVM impact separately > instead of treating it as the same UAF without supporting evidence. > > > Does this allow L2 to resume with unpinned HPAs and lead to a > > use-after-free? > > Not uniformly across these paths. The unpinned-HPA mechanism is the > concern for the nVMX VMCS02 address fields described in the patch, but I > have not yet reproduced host-page reuse or an actual use-after-free end > to end. For eVMCS and SVM, the current evidence establishes that the > deferred setup request can be lost; it does not yet establish the same > unpinned-HPA mechanism. > > I will also correct the commit message. Not every failure reports > KVM_EXIT_INTERNAL_ERROR: the load_pdptrs() failure used by my RSM > reproducer returns with exit_reason unchanged, which is > KVM_EXIT_UNKNOWN in the test. Heh, which as I pointed out in my other reply, is a bug, not intentional.