[PATCH] KVM: x86: Disallow EFER.LMSLE when EferLmsleUnsupported is set in guest CPUID

Jim Mattson posted 1 patch 6 days, 7 hours ago
arch/x86/kvm/msrs.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
[PATCH] KVM: x86: Disallow EFER.LMSLE when EferLmsleUnsupported is set in guest CPUID
Posted by Jim Mattson 6 days, 7 hours ago
Reject guest writes to EFER (and nested VMRUN with VMCB12 EFER) that set
EFER.LMSLE when CPUID.80000008H:EBX.EferLmsleUnsupported[bit 20] is set
in the guest's CPUID.

Commit c53c632592a4 ("KVM: SVM: Disallow EFER.LMSLE when not supported by
hardware") prevented EFER.LMSLE from being enabled in supported_efer_bits
on hosts that set EferLmsleUnsupported, but missed checking the guest
CPUID capability in __kvm_valid_efer(). As a result, on a host that
supports EFER.LMSLE (e.g. Rome), a guest whose userspace VMM sets
EferLmsleUnsupported in guest CPUID (e.g. for migration compatibility
with Milan, Genoa, or Turin) can still set EFER.LMSLE without triggering
a #GP.

Fixes: c53c632592a4 ("KVM: SVM: Disallow EFER.LMSLE when not supported by hardware")
Assisted-by: LLM
Signed-off-by: Jim Mattson <jmattson@google.com>
---
 arch/x86/kvm/msrs.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/arch/x86/kvm/msrs.c b/arch/x86/kvm/msrs.c
index dd3bb04878ca..6dbaf063cc8d 100644
--- a/arch/x86/kvm/msrs.c
+++ b/arch/x86/kvm/msrs.c
@@ -598,8 +598,11 @@ static bool __kvm_valid_efer(struct kvm_vcpu *vcpu, u64 efer)
 	if (efer & EFER_NX && !guest_cpu_cap_has(vcpu, X86_FEATURE_NX))
 		return false;
 
-	return true;
+	if (efer & EFER_LMSLE &&
+	    guest_cpu_cap_has(vcpu, X86_FEATURE_EFER_LMSLE_MBZ))
+		return false;
 
+	return true;
 }
 bool kvm_valid_efer(struct kvm_vcpu *vcpu, u64 efer)
 {
-- 
2.55.0.1082.g2b9226bbc0-goog
Re: [PATCH] KVM: x86: Disallow EFER.LMSLE when EferLmsleUnsupported is set in guest CPUID
Posted by Sean Christopherson 6 days, 7 hours ago
On Fri, Sep 18, 2026, Jim Mattson wrote:
> Reject guest writes to EFER (and nested VMRUN with VMCB12 EFER) that set
> EFER.LMSLE when CPUID.80000008H:EBX.EferLmsleUnsupported[bit 20] is set
> in the guest's CPUID.
> 
> Commit c53c632592a4 ("KVM: SVM: Disallow EFER.LMSLE when not supported by
> hardware") prevented EFER.LMSLE from being enabled in supported_efer_bits
> on hosts that set EferLmsleUnsupported, but missed checking the guest
> CPUID capability in __kvm_valid_efer(). As a result, on a host that
> supports EFER.LMSLE (e.g. Rome), a guest whose userspace VMM sets
> EferLmsleUnsupported in guest CPUID (e.g. for migration compatibility
> with Milan, Genoa, or Turin) can still set EFER.LMSLE without triggering
> a #GP.
> 
> Fixes: c53c632592a4 ("KVM: SVM: Disallow EFER.LMSLE when not supported by hardware")
> Assisted-by: LLM
> Signed-off-by: Jim Mattson <jmattson@google.com>
> ---
>  arch/x86/kvm/msrs.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
> 
> diff --git a/arch/x86/kvm/msrs.c b/arch/x86/kvm/msrs.c
> index dd3bb04878ca..6dbaf063cc8d 100644
> --- a/arch/x86/kvm/msrs.c
> +++ b/arch/x86/kvm/msrs.c
> @@ -598,8 +598,11 @@ static bool __kvm_valid_efer(struct kvm_vcpu *vcpu, u64 efer)
>  	if (efer & EFER_NX && !guest_cpu_cap_has(vcpu, X86_FEATURE_NX))
>  		return false;
>  
> -	return true;
> +	if (efer & EFER_LMSLE &&
> +	    guest_cpu_cap_has(vcpu, X86_FEATURE_EFER_LMSLE_MBZ))
> +		return false;
>  
> +	return true;

In case anyone else was wondering, this is NOT whitespace damage, the "movement"
of the "return true" is due to deleting a trailing spurious newline, e.g. my
configuration of diff yeilds:

diff --git a/arch/x86/kvm/msrs.c b/arch/x86/kvm/msrs.c
index dd3bb04878ca..6dbaf063cc8d 100644
--- a/arch/x86/kvm/msrs.c
+++ b/arch/x86/kvm/msrs.c
@@ -598,8 +598,11 @@ static bool __kvm_valid_efer(struct kvm_vcpu *vcpu, u64 efer)
 	if (efer & EFER_NX && !guest_cpu_cap_has(vcpu, X86_FEATURE_NX))
 		return false;
 
+	if (efer & EFER_LMSLE &&
+	    guest_cpu_cap_has(vcpu, X86_FEATURE_EFER_LMSLE_MBZ))
+		return false;
+
 	return true;
-
 }
 bool kvm_valid_efer(struct kvm_vcpu *vcpu, u64 efer)
 {