mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org, "Paolo Bonzini" <pbonzini@redhat.com>,
	"Andy Honig" <ahonig@google.com>
Subject: [PATCH 3.2 25/79] KVM: x86: Convert vapic synchronization to _cached functions  (CVE-2013-6368)
Date: Wed, 12 Feb 2014 08:10:12 +0000	[thread overview]
Message-ID: <lsq.1392192612.104543523@decadent.org.uk> (raw)
In-Reply-To: <lsq.1392192611.998273004@decadent.org.uk>

3.2.55-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Andy Honig <ahonig@google.com>

commit fda4e2e85589191b123d31cdc21fd33ee70f50fd upstream.

In kvm_lapic_sync_from_vapic and kvm_lapic_sync_to_vapic there is the
potential to corrupt kernel memory if userspace provides an address that
is at the end of a page.  This patches concerts those functions to use
kvm_write_guest_cached and kvm_read_guest_cached.  It also checks the
vapic_address specified by userspace during ioctl processing and returns
an error to userspace if the address is not a valid GPA.

This is generally not guest triggerable, because the required write is
done by firmware that runs before the guest.  Also, it only affects AMD
processors and oldish Intel that do not have the FlexPriority feature
(unless you disable FlexPriority, of course; then newer processors are
also affected).

Fixes: b93463aa59d6 ('KVM: Accelerated apic support')

Reported-by: Andrew Honig <ahonig@google.com>
Signed-off-by: Andrew Honig <ahonig@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
[dannf: backported to Debian's 3.2]
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
--- a/arch/x86/kvm/lapic.c
+++ b/arch/x86/kvm/lapic.c
@@ -1278,14 +1278,12 @@ void __kvm_migrate_apic_timer(struct kvm
 void kvm_lapic_sync_from_vapic(struct kvm_vcpu *vcpu)
 {
 	u32 data;
-	void *vapic;
 
 	if (!irqchip_in_kernel(vcpu->kvm) || !vcpu->arch.apic->vapic_addr)
 		return;
 
-	vapic = kmap_atomic(vcpu->arch.apic->vapic_page, KM_USER0);
-	data = *(u32 *)(vapic + offset_in_page(vcpu->arch.apic->vapic_addr));
-	kunmap_atomic(vapic, KM_USER0);
+	kvm_read_guest_cached(vcpu->kvm, &vcpu->arch.apic->vapic_cache, &data,
+				sizeof(u32));
 
 	apic_set_tpr(vcpu->arch.apic, data & 0xff);
 }
@@ -1295,7 +1293,6 @@ void kvm_lapic_sync_to_vapic(struct kvm_
 	u32 data, tpr;
 	int max_irr, max_isr;
 	struct kvm_lapic *apic;
-	void *vapic;
 
 	if (!irqchip_in_kernel(vcpu->kvm) || !vcpu->arch.apic->vapic_addr)
 		return;
@@ -1310,17 +1307,22 @@ void kvm_lapic_sync_to_vapic(struct kvm_
 		max_isr = 0;
 	data = (tpr & 0xff) | ((max_isr & 0xf0) << 8) | (max_irr << 24);
 
-	vapic = kmap_atomic(vcpu->arch.apic->vapic_page, KM_USER0);
-	*(u32 *)(vapic + offset_in_page(vcpu->arch.apic->vapic_addr)) = data;
-	kunmap_atomic(vapic, KM_USER0);
+	kvm_write_guest_cached(vcpu->kvm, &vcpu->arch.apic->vapic_cache, &data,
+				sizeof(u32));
 }
 
-void kvm_lapic_set_vapic_addr(struct kvm_vcpu *vcpu, gpa_t vapic_addr)
+int kvm_lapic_set_vapic_addr(struct kvm_vcpu *vcpu, gpa_t vapic_addr)
 {
 	if (!irqchip_in_kernel(vcpu->kvm))
-		return;
+		return 0;
+
+	if (vapic_addr && kvm_gfn_to_hva_cache_init(vcpu->kvm,
+					  &vcpu->arch.apic->vapic_cache,
+					  vapic_addr, sizeof(u32)))
+		return -EINVAL;
 
 	vcpu->arch.apic->vapic_addr = vapic_addr;
+	return 0;
 }
 
 int kvm_x2apic_msr_write(struct kvm_vcpu *vcpu, u32 msr, u64 data)
--- a/arch/x86/kvm/lapic.h
+++ b/arch/x86/kvm/lapic.h
@@ -15,7 +15,7 @@ struct kvm_lapic {
 	bool irr_pending;
 	void *regs;
 	gpa_t vapic_addr;
-	struct page *vapic_page;
+	struct gfn_to_hva_cache vapic_cache;
 };
 int kvm_create_lapic(struct kvm_vcpu *vcpu);
 void kvm_free_lapic(struct kvm_vcpu *vcpu);
@@ -45,7 +45,7 @@ int kvm_lapic_find_highest_irr(struct kv
 u64 kvm_get_lapic_tscdeadline_msr(struct kvm_vcpu *vcpu);
 void kvm_set_lapic_tscdeadline_msr(struct kvm_vcpu *vcpu, u64 data);
 
-void kvm_lapic_set_vapic_addr(struct kvm_vcpu *vcpu, gpa_t vapic_addr);
+int kvm_lapic_set_vapic_addr(struct kvm_vcpu *vcpu, gpa_t vapic_addr);
 void kvm_lapic_sync_from_vapic(struct kvm_vcpu *vcpu);
 void kvm_lapic_sync_to_vapic(struct kvm_vcpu *vcpu);
 
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -3140,8 +3140,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
 		r = -EFAULT;
 		if (copy_from_user(&va, argp, sizeof va))
 			goto out;
-		r = 0;
-		kvm_lapic_set_vapic_addr(vcpu, va.vapic_addr);
+		r = kvm_lapic_set_vapic_addr(vcpu, va.vapic_addr);
 		break;
 	}
 	case KVM_X86_SETUP_MCE: {
@@ -5537,33 +5536,6 @@ static void post_kvm_run_save(struct kvm
 			!kvm_event_needs_reinjection(vcpu);
 }
 
-static void vapic_enter(struct kvm_vcpu *vcpu)
-{
-	struct kvm_lapic *apic = vcpu->arch.apic;
-	struct page *page;
-
-	if (!apic || !apic->vapic_addr)
-		return;
-
-	page = gfn_to_page(vcpu->kvm, apic->vapic_addr >> PAGE_SHIFT);
-
-	vcpu->arch.apic->vapic_page = page;
-}
-
-static void vapic_exit(struct kvm_vcpu *vcpu)
-{
-	struct kvm_lapic *apic = vcpu->arch.apic;
-	int idx;
-
-	if (!apic || !apic->vapic_addr)
-		return;
-
-	idx = srcu_read_lock(&vcpu->kvm->srcu);
-	kvm_release_page_dirty(apic->vapic_page);
-	mark_page_dirty(vcpu->kvm, apic->vapic_addr >> PAGE_SHIFT);
-	srcu_read_unlock(&vcpu->kvm->srcu, idx);
-}
-
 static void update_cr8_intercept(struct kvm_vcpu *vcpu)
 {
 	int max_irr, tpr;
@@ -5836,7 +5808,6 @@ static int __vcpu_run(struct kvm_vcpu *v
 	}
 
 	vcpu->srcu_idx = srcu_read_lock(&kvm->srcu);
-	vapic_enter(vcpu);
 
 	r = 1;
 	while (r > 0) {
@@ -5893,8 +5864,6 @@ static int __vcpu_run(struct kvm_vcpu *v
 
 	srcu_read_unlock(&kvm->srcu, vcpu->srcu_idx);
 
-	vapic_exit(vcpu);
-
 	return r;
 }
 


  parent reply	other threads:[~2014-02-12  8:15 UTC|newest]

Thread overview: 83+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-02-12  8:10 [PATCH 3.2 00/79] 3.2.55-rc1 review Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 44/79] libata: disable a disk via libata.force params Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 37/79] xhci: Limit the spurious wakeup fix only to HP machines Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 65/79] ahci: add PCI ID for Marvell 88SE9170 SATA controller Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 23/79] hpfs: fix warnings when the filesystem fills up Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 57/79] drm/radeon: 0x9649 is SUMO2 not SUMO Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 34/79] ext4: check for overlapping extents in ext4_valid_extent_entries() Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 17/79] net: avoid reference counter overflows on fib_rules in multicast forwarding Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 42/79] radiotap: fix bitmap-end-finding buffer overrun Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 79/79] sched/rt: Avoid updating RT entry timeout twice within one tick period Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 32/79] ext4: call ext4_error_inode() if jbd2_journal_dirty_metadata() fails Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 10/79] rds: prevent dereference of a NULL device Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 50/79] ath9k: Fix interrupt handling for the AR9002 family Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 62/79] ahci: Use PCI_VENDOR_ID_MARVELL_EXT for 0x1b4b Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 30/79] sh: always link in helper functions extracted from libgcc Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 28/79] ceph: cleanup aborted requests when re-sending requests Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 19/79] PCI: Enable ARI if dev and upstream bridge support it; disable otherwise Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 20/79] mm/memory-failure.c: recheck PageHuge() after hugetlb page migrate successfully Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 09/79] hamradio/yam: fix info leak in ioctl Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 33/79] ext4: fix use-after-free in ext4_mb_new_blocks Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 15/79] bnx2x: fix DMA unmapping of TSO split BDs Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 61/79] powerpc: Fix bad stack check in exception entry Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 35/79] ext2: Fix oops in ext2_get_block() called from ext2_quota_write() Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 41/79] gpio: msm: Fix irq mask/unmask by writing bits instead of numbers Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 48/79] drm/i915: Use the correct GMCH_CTRL register for Sandybridge+ Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 70/79] md/raid10: fix bug when raid10 recovery fails to recover a block Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 67/79] SELinux: Fix possible NULL pointer dereference in selinux_inode_permission() Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 04/79] net: drop_monitor: fix the value of maxattr Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 49/79] rtlwifi: pci: Fix oops on driver unload Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 54/79] dm9601: fix reception of full size ethernet frames on dm9620/dm9621a Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 03/79] ipv6: don't count addrconf generated routes against gc limit Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 75/79] mm: hugetlbfs: fix hugetlbfs optimization Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 53/79] net_dma: mark broken Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 73/79] perf/x86/amd/ibs: Fix waking up from S3 for AMD family 10h Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 26/79] x86, fpu, amd: Clear exceptions in AMD FXSAVE workaround Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 46/79] sched/rt: Fix rq's cpupri leak while enqueue/dequeue child RT entities Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 08/79] drivers/net/hamradio: Integer overflow in hdlcdrv_ioctl() Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 43/79] ftrace: Initialize the ftrace profiler for each possible cpu Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 39/79] drm/radeon: Fix sideport problems on certain RS690 boards Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 64/79] pci: Add PCI_DEVICE_SUB() macro Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 38/79] iscsi-target: Fix-up all zero data-length CDBs with R/W_BIT set Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 31/79] libata: add ATA_HORKAGE_BROKEN_FPDMA_AA quirk for Seagate Momentus SpinPoint M8 Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 52/79] ASoC: wm8904: fix DSP mode B configuration Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 12/79] vlan: Fix header ops passthru when doing TX VLAN offload Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 69/79] md/raid10: fix two bugs in handling of known-bad-blocks Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 27/79] mm: ensure get_unmapped_area() returns higher address than mmap_min_addr Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 14/79] bridge: use spin_lock_bh() in br_multicast_set_hash_max Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 68/79] md/raid5: Fix possible confusion when multiple write errors occur Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 55/79] dm9601: work around tx fifo sync issue on dm962x Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 72/79] nilfs2: fix segctor bug that causes file system corruption Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 02/79] rds: prevent BUG_ON triggered on congestion update to loopback Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 24/79] ath9k_htc: properly set MAC address and BSSID mask Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 56/79] ext4: add explicit casts when masking cluster sizes Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 74/79] mm: fix aio performance regression for database caused by THP Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 71/79] hwmon: (coretemp) Fix truncated name of alarm attributes Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 51/79] cpupower: Fix segfault due to incorrect getopt_long arugments Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 06/79] net: unix: allow bind to fail on mutex lock Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 60/79] ARM: fix footbridge clockevent device Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 47/79] ALSA: Add SNDRV_PCM_STATE_PAUSED case in wait_for_avail function Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 16/79] inet_diag: fix inet_diag_dump_icsk() timewait socket state logic Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 78/79] sched: Unthrottle rt runqueues in __disable_runtime() Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 21/79] staging: comedi: cb_pcidio: fix for newer PCI-DIO48H Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 45/79] drm/ttm: Fix accesses through vmas with only partial coverage Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 40/79] ALSA: hda - Add enable_msi=0 workaround for four HP machines Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 13/79] net: llc: fix use after free in llc_ui_recvmsg Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 58/79] selinux: fix broken peer recv check Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 59/79] selinux: selinux_setprocattr()->ptrace_parent() needs rcu_read_lock() Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 07/79] net: inet_diag: zero out uninitialized idiag_{src,dst} fields Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 18/79] xfs: Account log unmount transaction correctly Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 11/79] net: rose: restore old recvmsg behavior Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 76/79] sched/rt: Fix SCHED_RR across cgroups Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 77/79] sched,rt: fix isolated CPUs leaving root_task_group indefinitely throttled Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 66/79] ARM: fix "bad mode in ... handler" message for undefined instructions Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 22/79] [IA64] Fix warning from machine_kexec.c Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 05/79] tg3: Initialize REG_BASE_ADDR at PCI config offset 120 to 0 Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 36/79] ext4: fix del_timer() misuse for ->s_err_report Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 29/79] ceph: wake up 'safe' waiters when unregistering request Ben Hutchings
2014-02-12  8:10 ` [PATCH 3.2 63/79] ahci: add an observed PCI ID for Marvell 88se9172 SATA controller Ben Hutchings
2014-02-12  8:10 ` Ben Hutchings [this message]
2014-02-12  8:10 ` [PATCH 3.2 01/79] net: do not pretend FRAGLIST support Ben Hutchings
2014-02-12  8:16 ` [PATCH 3.2 00/79] 3.2.55-rc1 review Ben Hutchings
2014-02-12 11:50 ` Guenter Roeck
2014-02-12 18:14   ` Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=lsq.1392192612.104543523@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=ahonig@google.com \
    --cc=akpm@linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®