From nobody Thu Aug 13 09:21:39 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=cit.tum.de ARC-Seal: i=1; a=rsa-sha256; t=1786095220; cv=none; d=zohomail.com; s=zohoarc; b=dl3abslKhvjR5CAEMnKAOUVunWaNsVZzaqd55ZXNbk1K1X5QuYL2pEVcEM0/gjfnSHSScsH3uFQqAMkP0ZYl4IBUJzrd+4KNqdC7WK5HMYlZgFNZs/ip9H1QAjRdf3EHv/5pPjiD1fLwYTc07+IyDco/3WCl3ZGuQvTlmtpiU+k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786095220; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Z3p8olyxZ32+8cGkN/ra6kddtLV2OiPHtOEbdJxzTvw=; b=c4cj+R++hmBDjLUQp9fTInibHQZ7D94+ZclIhUpaVhAb35TX5xVZDIIZ1wNfaTLrGQ+xVepyVkzcUA97jdqGd0V9/UN94LmlZyGmGOuAaPqizEGAdwlhAwRLu6PbrrRtOtZ+tV8QMTb7F4gv0TUXAfHp8qNrENByV3OujhxeAGM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1786095220084695.344628190591; Fri, 7 Aug 2026 02:33:40 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1385875.1628213 (Exim 4.92) (envelope-from ) id 1wsGwl-0002i6-Ur; Fri, 07 Aug 2026 09:32:59 +0000 Received: by outflank-mailman (output) from mailman id 1385875.1628213; Fri, 07 Aug 2026 09:32:59 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wsGwl-0002hz-S9; Fri, 07 Aug 2026 09:32:59 +0000 Received: by outflank-mailman (input) for mailman id 1385875; Fri, 07 Aug 2026 09:32:59 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wsGwk-0002ht-Li for xen-devel@lists.xenproject.org; Fri, 07 Aug 2026 09:32:59 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wsGwk-00AXZx-2W for xen-devel@lists.xenproject.org; Fri, 07 Aug 2026 11:32:58 +0200 Received: from [10.42.69.7] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a75a649-bab6-0a2a0a5309dd-0a2a4507b28e-6 for ; Fri, 07 Aug 2026 11:32:57 +0200 Received: from [131.159.0.202] (helo=mailout2.rbg.tum.de) by tlsNG-ef75cf.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a75a649-b4ea-0a2a45070019-839f00cae863-3 for ; Fri, 07 Aug 2026 11:32:57 +0200 Received: from mailrelay1n.ito.cit.tum.de (mailrelay.in.tum.de [131.159.254.10]) by mailout2.rbg.tum.de (Postfix) with ESMTPS id E856C4C0285; Fri, 7 Aug 2026 11:32:56 +0200 (CEST) Received: from mail.in.tum.de (vmrbg426.in.tum.de [131.159.0.73]) by mailrelay1n.ito.cit.tum.de (Postfix) with ESMTPS id 4hGf885Wngz2xTS; Fri, 7 Aug 2026 11:32:56 +0200 (CEST) Received: by mail.in.tum.de (Postfix, from userid 112) id BC2E04A04C1; Fri, 7 Aug 2026 11:32:56 +0200 (CEST) Received: (Authenticated sender: hoepf) by mail.in.tum.de (Postfix) with ESMTPSA id 903A74A0425; Fri, 7 Aug 2026 11:32:56 +0200 (CEST) (Extended-Queue-bit xtech_ja@fff.in.tum.de) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=20220209 header.d=cit.tum.de header.i="@cit.tum.de" header.h="Date:From:To:Cc:Subject:References:In-Reply-To" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cit.tum.de; s=20220209; t=1786095176; bh=Z3p8olyxZ32+8cGkN/ra6kddtLV2OiPHtOEbdJxzTvw=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=OVrl0+BRIokrzr4rCeMINBhIvom/UiDN0tOeYeRH4VE675ijh06oyIQHhBrdnadlh /RhojvqJZ7cFaGk9pIaeWiNQ1rz2N+6d8keSh9et9y3gytnofPNjIphXF24seNqvIQ ICyfWJf6gyXY+FVpHDRFZ/H7/UmvlqzQKOrNpVnBiq95D8+WEuhrQHBqnWLPomQL4Q u9mX13Qt22FbdgJ7EBZmTbLF2g74E5W0KhJ/CD6vMqS9hHLGWj5GveDh23+3u47KS6 jMUxp1TgNKgNIS53FfYyE2ZtJZswY8EsAjGWizR20aqZ7RdT47cbkV/5PcXKL4/Hbt Fg3+RvFjxNrog== Date: Fri, 7 Aug 2026 11:32:55 +0200 From: Johann =?utf-8?Q?H=C3=B6pfner?= To: Jan Beulich Cc: xen-devel@lists.xenproject.org, Andrew Cooper , Roger Pau =?utf-8?B?TW9ubsOp?= , Teddy Astie Subject: [PATCH] vvmx: Fix uninitialised writeback to vmcs12 Message-ID: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Disposition: inline Content-Transfer-Encoding: quoted-printable In-Reply-To: X-Virus-Scanned: clamav-milter 1.5.3 at itovm121 X-Virus-Status: Clean X-purgate-ID: tlsNG-ef75cf/1786095177-348C9AE4-312987C3/0/0 X-purgate-type: clean X-purgate-size: 2381 X-Zoho-Virus-Status: 1 X-Zoho-AV-Stamp: zmail-av-0.2.10.1.5.2/286.87.57 X-ZohoMail-DKIM: pass (identity @cit.tum.de) X-ZM-MESSAGEID: 1786095226983158500 nvmx_handle_vmwrite leaves local eight byte variable 'operand' uninitialised to be written as an out-parameter by decode_vmx_inst. In cases where the operand to vmwrite is a 32 bit memory operand, the invokation of hvm_copy_from_guest_linear leaves the upper half of *poperandS uninitialised. The resulting eight byte value is consequently written to the vmcs12 leaking the four uninitialised bytes into guest physical memory. Initialize the stack-space passed to decode_vmx_inst to avoid this issue. Fixes: 2b2793d3ae44 ("nEPT: handle invept instruction from L1 VMM") Fixes: d4c5b9db5a85 ("Nested VMX: Emulation of guest VMWRITE") Fixes: 9ccf55307868 ("nVMX: virutalize VPID capability to nested VMM") Signed-off-by: Johann H=C3=B6pfner --- > In any event - why don't you make your proposed change into a proper patch > (primary piece missing is your S-o-b, and perhaps we also would want a > suitable Fixes: tag)? Sorry to have kept you waiting. Here is the formatted patch. I included the invvpid case still, though I believe only vmwrite remains after the patch you linked is merged, right? xen/arch/x86/hvm/vmx/vvmx.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/xen/arch/x86/hvm/vmx/vvmx.c b/xen/arch/x86/hvm/vmx/vvmx.c index e4cdfe55c1..68c5df6658 100644 --- a/xen/arch/x86/hvm/vmx/vvmx.c +++ b/xen/arch/x86/hvm/vmx/vvmx.c @@ -1968,7 +1968,7 @@ static int nvmx_handle_vmwrite(struct cpu_user_regs *= regs) { struct vcpu *v =3D current; struct vmx_inst_decoded decode; - unsigned long operand;=20 + unsigned long operand =3D 0; u64 vmcs_encoding; enum vmx_insn_errno err; int rc; @@ -2012,7 +2012,7 @@ static int nvmx_handle_vmwrite(struct cpu_user_regs *= regs) static int nvmx_handle_invept(struct cpu_user_regs *regs) { struct vmx_inst_decoded decode; - unsigned long eptp; + unsigned long eptp =3D 0; int ret; =20 if ( (ret =3D decode_vmx_inst(regs, &decode, &eptp)) !=3D X86EMUL_OKAY= ) @@ -2040,7 +2040,7 @@ static int nvmx_handle_invept(struct cpu_user_regs *r= egs) static int nvmx_handle_invvpid(struct cpu_user_regs *regs) { struct vmx_inst_decoded decode; - unsigned long vpid; + unsigned long vpid =3D 0; int ret; =20 if ( (ret =3D decode_vmx_inst(regs, &decode, &vpid)) !=3D X86EMUL_OKAY= ) --=20 2.53.0