From nobody Thu Jul 23 21:12:16 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=citrix.com ARC-Seal: i=1; a=rsa-sha256; t=1784036188; cv=none; d=zohomail.com; s=zohoarc; b=YX6ez+E+2tMD/57B4pffN01KbrX0XhXy/pbUgEIRm1/tPnS2+GvGCI9P/vk3y83+ElkjdSJ7s+RsWxb76KElR2gyM/s2bCpWhnkqszRe9vaPThg9DMpKlv1tJxlHE91FHviwAE6gO8PIh52vdbSR55tSTvWme9MNIt51QjlfOOY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784036188; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gcX74k/358IG8rk50bDhHQk6v6yxS+6nIWIEc4UqUHw=; b=ElyibF4EuUZqTVWTZ78vTiMnVSxTTLdeQLRFWeOmfszOioQvQkkocF0pQayyYAqWhLpVcPAzmoMc06jTNk5RuwezdbI2e3mVx3EP2S9bbM70tFGoxkdcVh8mNkYVG3iK45snV0ycI3IVqEYiUxCnfxZ2l5NrXSEnha617VlHFv4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784036187970131.22161966914518; Tue, 14 Jul 2026 06:36:27 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1362390.1614214 (Exim 4.92) (envelope-from ) id 1wjdId-00013A-8u; Tue, 14 Jul 2026 13:35:51 +0000 Received: by outflank-mailman (output) from mailman id 1362390.1614214; Tue, 14 Jul 2026 13:35:51 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wjdId-000133-67; Tue, 14 Jul 2026 13:35:51 +0000 Received: by outflank-mailman (input) for mailman id 1362390; Tue, 14 Jul 2026 13:35:50 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) id 1wjdIc-00012x-Kq for xen-devel@lists.xenproject.org; Tue, 14 Jul 2026 13:35:50 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wjdIb-00BfDU-IF for xen-devel@lists.xenproject.org; Tue, 14 Jul 2026 15:35:49 +0200 Received: from [10.42.69.8] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a563b2d-2eae-0a2a0a5409dd-0a2a4508d934-20 for ; Tue, 14 Jul 2026 15:35:49 +0200 Received: from [209.85.221.53] (helo=mail-wr1-f53.google.com) by tlsNG-c1860d.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a563b35-f659-0a2a45080019-d155dd35d535-3 for ; Tue, 14 Jul 2026 15:35:49 +0200 Received: by mail-wr1-f53.google.com with SMTP id ffacd0b85a97d-47c6e9a694bso2404099f8f.1 for ; Tue, 14 Jul 2026 06:35:49 -0700 (PDT) Received: from localhost.localdomain (host-78-146-248-75.as13285.net. [78.146.248.75]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495087366c0sm145127875e9.7.2026.07.14.06.35.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 14 Jul 2026 06:35:47 -0700 (PDT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=google header.d=citrix.com header.i="@citrix.com" header.h="Content-Transfer-Encoding:Content-Type:MIME-Version:Message-Id:Date:Subject:Cc:To:From" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=citrix.com; s=google; t=1784036149; x=1784640949; darn=lists.xenproject.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=gcX74k/358IG8rk50bDhHQk6v6yxS+6nIWIEc4UqUHw=; b=dwHjF2nWiDeVJlaLr0XSBciPP/t+yvWVsYy+vnHJin8pKMk0zCsmD1/bGpHzkQ6/TV 2xMbcSQHPHDEFV0F31MFhvyF/8SgdrpefqBX81mbDqhGlShtsbevVq1DRQnqwhL3S+bJ QYdeWfcMVGL3chglntXRI+3PvZCZ2BZmKQgoA= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784036149; x=1784640949; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=gcX74k/358IG8rk50bDhHQk6v6yxS+6nIWIEc4UqUHw=; b=K9DVyXisK6aQ1AZi3NY+xpgQ/Q8aRRGJWhp9w7X/VgLF/Qul6PoDc1R4STu3AT4Zpe HGuOfJ1NHDKKPxhBokIcJVIrVKkAUwph43eg8WMNe7LWtZTOSAfuMUhzYK1mRxmsKWlj FyPco/cydIKLStHLEZQu/QsGoOGUrELq+zEWkaDPU1mVdsi0Z5v84hoRHJfezwv9/kmy BblqFLZC4yah5puzTspjgRcGrZzWJD5sOkMAoRXDTYFbQPdnru7hLBeszqUh/7z8pHwI P7o9onqEYJ8i49MfMqu1GhkzuC5hcs8OS1S/HXb6kpCLT1PoS+duTR7LK7btqc0LDni/ xpaQ== X-Gm-Message-State: AOJu0Yx4xvgZjvO/WC4JtrKhqmFp79tIlWFwq2QajSViE62l9t2bAXRS K0QSXm8ji34ZgftorIKYCCHp9pxzaSAUqMTAZm2OGGMlsC2CHUOJ4BbRSkwyzb7/sfexj7lhPqa ZvAh9 X-Gm-Gg: AfdE7cllT3nta4LCVVoMSF44hiz9WVMEU4/gV38sb//RW49pLjHmQl/spoBSka8yNdN 6FFSP/Yqjo7VriEjXXRsTbQzvzSmwRJveEHjva+AtIJ6A9txaTQk5R6PUx7+KUOXS2nbo+sxMH+ gY/85DG+orC+29eXdr2BLFYFHZjAt/at42k4pQ1FxovWLmpqbsNSok6hYlxPYqMoEUvdz7uSHXi H0R1y+MVIHrsbeiBATeEGCOA82g1qE8Tz/QudheaJcATEnRa0FD48hIAUWeOjb5gvyq/q16FjRk Zw2EEj+h4/3gdAQ1UnY0NvtQYwW8yKFvJ0KYYGmv4gJKMoEzMcobt60nx5mrjJve7RIIOZJCyfM C2g6gBP5qQPJ5dWiHDtPWhUoDC45uBSxEcQt3zRih4YJ7/TZ91HmlWhm3AiNhhl+MB2Lfk5g9/l S7V/QgByDAdbqj8yywbq93veeTLzvKFijvegFl1SKhVPy1u5BBFTXZ2ZMQcTiQhjI= X-Received: by 2002:a05:600c:8284:b0:493:a5f9:d33d with SMTP id 5b1f17b1804b1-493f8824395mr142823185e9.18.1784036148105; Tue, 14 Jul 2026 06:35:48 -0700 (PDT) From: Andrew Cooper To: Xen-devel Cc: Andrew Cooper , Jan Beulich , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Teddy Astie , Oleksii Kurochko Subject: [PATCH] x86/pv: Only use the guest frame in pv_map_ldt_shadow_page() Date: Tue, 14 Jul 2026 14:35:46 +0100 Message-Id: <20260714133546.1686108-1-andrew.cooper3@citrix.com> X-Mailer: git-send-email 2.39.5 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-purgate-ID: tlsNG-c1860d/1784036149-CF75B87B-CA0A27C3/10/73395122804 X-purgate-type: spam X-purgate-size: 2581 X-ZohoMail-DKIM: pass (identity @citrix.com) X-ZM-MESSAGEID: 1784036190291158500 pv_map_ldt_shadow_page() takes the whole guest PTE, adds _PAGE_RW to it, th= en installs it into Xen's pagetables. It has had this behaviour ever since LDT support was added in 2003. However, it allows the guest to control the software available bits and cacheability. This happens to be benign right now, but is bad form. Use only the guest frame, and construct the mapping as regular RW frame, and notably includes NX. This is how the GDT logic already works. Fixes: 005c2723972f ("Finished virtualisation of x86 LDT") Signed-off-by: Andrew Cooper Reviewed-by: Jan Beulich --- CC: Jan Beulich CC: Roger Pau Monn=C3=A9 CC: Teddy Astie CC: Oleksii Kurochko For 4.22. The security team have deemed this not an XSA, but it came alarmingly close. This was found originally in an LLM review of the ASI series, where a real vulnerability had been introduced by using one of the software available bi= ts to mean "please free this page on unmap". The LLM did not the issues with attributes (the guest could almost load a Shadow Stack mapping, saved only = by the forced addition of _PAGE_RW), and the cacheability (saved only because = of how conflicting MTRR and PAT values resolve). An interesting commit is 928a6621db20 ("Fix bug in new LDT shadow mapping code", 2003) which did restrict to the guest frame only, but without insert= ing _PAGE_PRESENT or any other attributes, so got reverted in the following com= mit 6841936e9256. --- xen/arch/x86/pv/mm.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/xen/arch/x86/pv/mm.c b/xen/arch/x86/pv/mm.c index 3f2e9dedcde3..5378299b8cef 100644 --- a/xen/arch/x86/pv/mm.c +++ b/xen/arch/x86/pv/mm.c @@ -53,7 +53,7 @@ bool pv_map_ldt_shadow_page(unsigned int offset) struct vcpu *curr =3D current; struct domain *currd =3D curr->domain; struct page_info *page; - l1_pgentry_t gl1e, *pl1e; + l1_pgentry_t gl1e, *pl1e, nl1e; unsigned long linear =3D curr->arch.pv.ldt_base + offset; =20 BUG_ON(in_irq()); @@ -88,9 +88,9 @@ bool pv_map_ldt_shadow_page(unsigned int offset) } =20 pl1e =3D &pv_ldt_ptes(curr)[offset >> PAGE_SHIFT]; - l1e_add_flags(gl1e, _PAGE_RW); + nl1e =3D l1e_from_pfn(l1e_get_pfn(gl1e), __PAGE_HYPERVISOR_RW); =20 - l1e_write(pl1e, gl1e); + l1e_write(pl1e, nl1e); =20 return true; } base-commit: e3aa330017c533cc312ee4751b8387d988682efc --=20 2.39.5