[PATCH] RISC-V: KVM: Fix sdata leak and stale snapshot_addr in snapshot_set_shmem

Zongmin Zhou posted 1 patch 1 month ago
arch/riscv/kvm/vcpu_pmu.c | 8 ++++++++
1 file changed, 8 insertions(+)
[PATCH] RISC-V: KVM: Fix sdata leak and stale snapshot_addr in snapshot_set_shmem
Posted by Zongmin Zhou 1 month ago
From: Zongmin Zhou <zhouzongmin@kylinos.cn>

A guest may call SBI_PMU_SNAPSHOT_SET_SHMEM repeatedly. Each call
overwrites kvpmu->sdata without freeing the old buffer (memory leak),
and if a later kvm_vcpu_write_guest() fails, the error path frees
sdata but leaves snapshot_addr stale. A subsequent
SBI_PMU_COUNTER_START then passes the INVALID_GPA check and crashes
the host with a NULL buffer in kvm_vcpu_read_guest().

Fix this by clearing the previously installed snapshot area before
installing a new one, which keeps sdata and snapshot_addr consistent.
The SBI spec suggests a single invocation but defines no error code
for repeated calls, so KVM must tolerate them.

Fixes: c2f41ddbcdd756 ("RISC-V: KVM: Implement SBI PMU Snapshot feature")
Cc: stable@vger.kernel.org
Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>
---
 arch/riscv/kvm/vcpu_pmu.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/arch/riscv/kvm/vcpu_pmu.c b/arch/riscv/kvm/vcpu_pmu.c
index 752f1014d633e7d67f69c27b72088ed560c187ac..14f73490f12cbc5a8547859f0d1bb1170d89403b 100644
--- a/arch/riscv/kvm/vcpu_pmu.c
+++ b/arch/riscv/kvm/vcpu_pmu.c
@@ -454,6 +454,14 @@ int kvm_riscv_vcpu_pmu_snapshot_set_shmem(struct kvm_vcpu *vcpu, unsigned long s
 		}
 	}
 
+	/*
+	 * Clear any previously installed snapshot area to avoid leaking
+	 * the old sdata and to keep sdata/snapshot_addr consistent if
+	 * the re-install fails below.
+	 */
+	if (kvpmu->snapshot_addr != INVALID_GPA)
+		kvm_pmu_clear_snapshot_area(vcpu);
+
 	kvpmu->sdata = kzalloc(snapshot_area_size, GFP_ATOMIC | __GFP_ACCOUNT);
 	if (!kvpmu->sdata) {
 		sbiret = SBI_ERR_FAILURE;
-- 
2.34.1


No virus found
		Checked by Hillstone Network AntiVirus
Re: [PATCH] RISC-V: KVM: Fix sdata leak and stale snapshot_addr in snapshot_set_shmem
Posted by Anup Patel 2 weeks, 1 day ago
On Wed, Aug 26, 2026 at 12:11 PM Zongmin Zhou <min_halo@163.com> wrote:
>
> From: Zongmin Zhou <zhouzongmin@kylinos.cn>
>
> A guest may call SBI_PMU_SNAPSHOT_SET_SHMEM repeatedly. Each call
> overwrites kvpmu->sdata without freeing the old buffer (memory leak),
> and if a later kvm_vcpu_write_guest() fails, the error path frees
> sdata but leaves snapshot_addr stale. A subsequent
> SBI_PMU_COUNTER_START then passes the INVALID_GPA check and crashes
> the host with a NULL buffer in kvm_vcpu_read_guest().
>
> Fix this by clearing the previously installed snapshot area before
> installing a new one, which keeps sdata and snapshot_addr consistent.
> The SBI spec suggests a single invocation but defines no error code
> for repeated calls, so KVM must tolerate them.
>
> Fixes: c2f41ddbcdd756 ("RISC-V: KVM: Implement SBI PMU Snapshot feature")
> Cc: stable@vger.kernel.org
> Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>

LGTM.

Reviewed-by: Anup Patel <anup@brainfault.org>

Queued this patch as fix for Linux-7.3-rcX

Thanks,
Anup


> ---
>  arch/riscv/kvm/vcpu_pmu.c | 8 ++++++++
>  1 file changed, 8 insertions(+)
>
> diff --git a/arch/riscv/kvm/vcpu_pmu.c b/arch/riscv/kvm/vcpu_pmu.c
> index 752f1014d633e7d67f69c27b72088ed560c187ac..14f73490f12cbc5a8547859f0d1bb1170d89403b 100644
> --- a/arch/riscv/kvm/vcpu_pmu.c
> +++ b/arch/riscv/kvm/vcpu_pmu.c
> @@ -454,6 +454,14 @@ int kvm_riscv_vcpu_pmu_snapshot_set_shmem(struct kvm_vcpu *vcpu, unsigned long s
>                 }
>         }
>
> +       /*
> +        * Clear any previously installed snapshot area to avoid leaking
> +        * the old sdata and to keep sdata/snapshot_addr consistent if
> +        * the re-install fails below.
> +        */
> +       if (kvpmu->snapshot_addr != INVALID_GPA)
> +               kvm_pmu_clear_snapshot_area(vcpu);
> +
>         kvpmu->sdata = kzalloc(snapshot_area_size, GFP_ATOMIC | __GFP_ACCOUNT);
>         if (!kvpmu->sdata) {
>                 sbiret = SBI_ERR_FAILURE;
> --
> 2.34.1
>
>
> No virus found
>                 Checked by Hillstone Network AntiVirus
>