From nobody Sat Oct 3 04:45:53 2026 Received: from out-173.mta0.migadu.com (out-173.mta0.migadu.com [91.218.175.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E0CA43FB7D5 for ; Wed, 5 Aug 2026 09:39:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922743; cv=none; b=mI/PBgTuFu5M9Q3pO6d9fy5Gu4kdw0h9U6eSIT6e7U2gEUipCmz3JCB4rYEuBj1ETME81QRCXmny2cg/A2iTmNb4wGnfYl3yIl09/SwTHyVOOYpEhxUiBoQsYxeyPtdFov2MNX0lQbcJByrFTaOQ8uiMKIE9c7lonU0qwgQy7FE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922743; c=relaxed/simple; bh=lTX9zw8nIo79IE+8hZKxtjCT2p3ZrPIQ/UhGZtPRTYs=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=AVT6b4XYsGXnNJ350VcKdXuwVaF86SOB9z24htbCeahW8KQ9Z1XVDjc/RPa1Dx8AkpcQiwqX+Hy0sKFDTH4eXgCwrGWrHdjOorf1obygk0O0hc6L5ld1WS6m013Z44Vd6TsXm96XdzQe0vpSGS86slGhLLV655kh8XLE10cAhsw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=Xd/dFTOE; arc=none smtp.client-ip=91.218.175.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="Xd/dFTOE" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1785922727; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=jvgbJlPCnE4f10jQC8pND6XdEzFjAYm1Jvqvul33sH8=; b=Xd/dFTOEJlqSxLRJtBna6CdPBBlF7rsbLMwYtyQjYIPfgMyDo/kJ3LTNzioNNL2Z3V85um sR9lUD0GQyq75c+7GI0q4jwAoWt/gSPMce2BXc2RZ9nhNAnDsfIM8mAXVPQsz3dWyL3x5P cZg8SfWE9OnAxkPJjLDQWtZVdsOJ8+Q= From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH 1/3] KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save Date: Wed, 5 Aug 2026 10:38:26 +0100 Message-Id: <20260805093828.3626610-2-fuad.tabba@linux.dev> In-Reply-To: <20260805093828.3626610-1-fuad.tabba@linux.dev> References: <20260805093828.3626610-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" MAPC with V=3D0 drops ite->collection but leaves the ITE on the device's ITT list, and vgic_its_save_ite() dereferences it unconditionally. A guest that issues MAPD, MAPTI and then MAPC(V=3D0) therefore oopses the host when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it. That sequence is UNPREDICTABLE per the architecture, but KVM already handles the resulting state in the translate, MOVI and DISCARD paths. Save a zeroed entry, which vgic_its_restore_ite() reads back as invalid. Skipping the ITE instead would leave the ITT slot holding whatever is in guest memory, and restore rejects an entry naming a collection the restored collection table does not have. Fixes: eff484e0298da ("KVM: arm64: vgic-its: ITT save and restore") Cc: stable@vger.kernel.org Signed-off-by: Fuad Tabba --- arch/arm64/kvm/vgic/vgic-its.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c index 36ab3e4929154..ed281fbf008b9 100644 --- a/arch/arm64/kvm/vgic/vgic-its.c +++ b/arch/arm64/kvm/vgic/vgic-its.c @@ -2119,6 +2119,14 @@ static int vgic_its_save_ite(struct vgic_its *its, s= truct its_device *dev, u32 next_offset; u64 val; =20 + /* + * MAPC with V=3D0 keeps the ITEs mapped but drops their collection, + * and with it the ICID. Save a zeroed entry, which the restore path + * reads back as invalid. + */ + if (!ite->collection) + return vgic_its_write_entry_lock(its, gpa, 0ULL, ite); + next_offset =3D compute_next_eventid_offset(&dev->itt_head, ite); val =3D ((u64)next_offset << KVM_ITS_ITE_NEXT_SHIFT) | ((u64)ite->irq->intid << KVM_ITS_ITE_PINTID_SHIFT) | --=20 2.39.5 From nobody Sat Oct 3 04:45:53 2026 Received: from out-173.mta0.migadu.com (out-173.mta0.migadu.com [91.218.175.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E81553F86E2 for ; Wed, 5 Aug 2026 09:39:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.173 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922742; cv=none; b=oOI0KuoAqkH/acywyEzeAqCtexHnjhLeCEGfLDMhODTBZBeMM2rDrd8u+koHEwz+DpyqgYrjueO2BPdDRkMZ3WArsnBgfauulkDchzrbi44frbRO9L/V7WKBvp1V53vzNQ1KSD13omOiEi8WMPKDzl+5fJSheZC18wq3/U4raCg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922742; c=relaxed/simple; bh=hpcT4mmWrsVBtuIsNOiEqSW7KDRvW75gMbMetYl4Cjk=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=SjcjTl+y3QZXnsHbdtB1tFMkonThRGf1UE3axVBzFGrN6/UWP6YFHUYQ4a8XzKY6uEHfKQNY21cbRpcxOOxdwV/PvxKvjLrKUXpGdZ6+tf3Y3QKoFikfwX1Oclq45kdHcU8skxKHomTv0cR7ozR7d0hTy37ywbFwRzC8EHQg7cY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=XSd/mzkQ; arc=none smtp.client-ip=91.218.175.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="XSd/mzkQ" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1785922735; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XQKyNwSgEBS1FdQPCr0BFf1gJZ2ngUj/l5kLW14oFV0=; b=XSd/mzkQQdJGkHoN7Z37EQc8KlR+Bm3kkIGiiyx1VrQ3/P/xPt2409QuZZt37dZWQkGSnh 09YUxF4ay+gMmOyBWfcYtZaykjNlwbiT9YHz6BZVURE9Yxj9yMJVlhUihAdGiVrYVquQmW X7C6sgB8nl//JT6bvcSppeLE3hA/GdE= From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH 2/3] KVM: arm64: vgic: Don't leak the SPI array when init is retried Date: Wed, 5 Aug 2026 10:38:27 +0100 Message-Id: <20260805093828.3626610-3-fuad.tabba@linux.dev> In-Reply-To: <20260805093828.3626610-1-fuad.tabba@linux.dev> References: <20260805093828.3626610-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" Nothing latches a failed vgic_init(), so userspace can retry KVM_DEV_ARM_VGIC_CTRL_INIT after a failure past kvm_vgic_dist_init(). kvm_vgic_setup_default_irq_routing() is the reachable case, running on every configuration. Each retry overwrites dist->spis and only the last allocation is freed at teardown, leaking up to 960 struct vgic_irq, about 90KB, per attempt. Return early when the array is already allocated, as vgic_allocate_private_irqs_locked() and vgic_v4_init() do. Fixes: ad275b8bb1e65 ("KVM: arm/arm64: vgic-new: vgic_init: implement vgic_= init") Signed-off-by: Fuad Tabba --- arch/arm64/kvm/vgic/vgic-init.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/arch/arm64/kvm/vgic/vgic-init.c b/arch/arm64/kvm/vgic/vgic-ini= t.c index 907057881b26a..d4cf143f3ae6b 100644 --- a/arch/arm64/kvm/vgic/vgic-init.c +++ b/arch/arm64/kvm/vgic/vgic-init.c @@ -210,6 +210,9 @@ static int kvm_vgic_dist_init(struct kvm *kvm, unsigned= int nr_spis) struct kvm_vcpu *vcpu0 =3D kvm_get_vcpu(kvm, 0); int i; =20 + if (dist->spis) + return 0; + dist->active_spis =3D (atomic_t)ATOMIC_INIT(0); dist->spis =3D kzalloc_objs(struct vgic_irq, nr_spis, GFP_KERNEL_ACCOUNT); if (!dist->spis) --=20 2.39.5 From nobody Sat Oct 3 04:45:53 2026 Received: from out-180.mta0.migadu.com (out-180.mta0.migadu.com [91.218.175.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2CA8F3FBB67 for ; Wed, 5 Aug 2026 09:39:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922746; cv=none; b=LSi/0PHuzrlO8NfRVR5oavLgbCpm+pfMCg4F3rwTji/Rf/NeHZWOlUA96cNJle7VInG1QeTf141SM0u0Tk0+vszZpNUMfcoSItFewbAgVKcnsUDQaoXzHBgLKCWLrOhnKaJVQsGcksVyvnqR6IePVpR36q0af243E7YAFVDce6M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785922746; c=relaxed/simple; bh=43nIU2EkqeEwkSPw2nRlklzH3Ir/5IlnjdHXbjU4Dts=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=KyJSW+b/6DeKQ2Xg0tBPKvQCaZ+3jtWudeAbEUpVIGY76rnAAFVpjXAoH4bN8bZbOt9xQOchPXYN4tMHPr/mh1pYdT9yjQaUsANYKm6bpe9ZHRgXpJb4G3OTSPxBISmIvoBdZ5ggZDB8zXddCjhsJvpIK5DN465dlqxGXufr5LA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev; spf=pass smtp.mailfrom=linux.dev; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b=HKh4IXIv; arc=none smtp.client-ip=91.218.175.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.dev Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.dev Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linux.dev header.i=@linux.dev header.b="HKh4IXIv" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linux.dev; s=key1; t=1785922741; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=rPDR+Ax2mjvgE26rYgUW+aQnYDPjJl0AyLsMcbzCS2k=; b=HKh4IXIvqrrAd7KFVo/dSmdjPRRZMObTmeFaKbo5EMkOmXXM+1o86Ee0aN/gyM/SzcPAnJ q68WWH/Xtvr3kpy/Mgn/KTFGjaWSu8EuI7GlcrwH4K1bz/0GzWHXWB1yrd3u9f935NnRB0 jrFbV/x1AQD13RPGtMysx7Wje4vSNXM= From: Fuad Tabba To: Marc Zyngier , Oliver Upton Cc: Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Will Deacon , Sascha Bischoff , Sebastian Ene , kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH 3/3] KVM: arm64: vgic-its: Don't write past the end of the collection table Date: Wed, 5 Aug 2026 10:38:28 +0100 Message-Id: <20260805093828.3626610-4-fuad.tabba@linux.dev> In-Reply-To: <20260805093828.3626610-1-fuad.tabba@linux.dev> References: <20260805093828.3626610-1-fuad.tabba@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" vgic_its_save_collection_table() computes max_size but uses it only to decide whether to append a terminator, leaving the walk over its->collection_list unbounded. A guest that disables the ITS and rewrites GITS_BASER with fewer pages, VALID still set, keeps every collection it mapped against the larger table, because KVM stores the new BASER unconditionally and frees the list only when VALID is cleared. A save then writes up to 448K past the end of the table. The writes stay in guest memory, as vgic_write_guest_lock() validates every gfn, so the guest only corrupts itself. Stop at the boundary regardless and return -EINVAL, which is what vgic_its_save_device_tables() returns when a device falls outside its own table. -ENOSPC describes the condition better, but -EINVAL is already in the error set documented for KVM_DEV_ARM_VGIC_GRP_CTRL, and -ENOSPC is not. Fixes: ea1ad53e1e31a ("KVM: arm64: vgic-its: Collection table save/restore") Signed-off-by: Fuad Tabba --- arch/arm64/kvm/vgic/vgic-its.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/arch/arm64/kvm/vgic/vgic-its.c b/arch/arm64/kvm/vgic/vgic-its.c index ed281fbf008b9..c709fc5e17cda 100644 --- a/arch/arm64/kvm/vgic/vgic-its.c +++ b/arch/arm64/kvm/vgic/vgic-its.c @@ -2540,6 +2540,9 @@ static int vgic_its_save_collection_table(struct vgic= _its *its) max_size =3D GITS_BASER_NR_PAGES(baser) * SZ_64K; =20 list_for_each_entry(collection, &its->collection_list, coll_list) { + if (filled =3D=3D max_size) + return -EINVAL; + ret =3D vgic_its_save_cte(its, collection, gpa); if (ret) return ret; --=20 2.39.5