From nobody Thu Sep 24 13:39:03 2026 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 62D285208B1 for ; Wed, 23 Sep 2026 15:51:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790178680; cv=none; b=sCb0PZdJV/Z5h2kK/Lp94tMnB0fd37iD6zlgqS+w8CK4snhJxJOXqI/zfaXu5kQCwOssC2NXAWlyhus2i+rp4VpL/8Rdu90eySEwCaRyNhGI5vWHpX21ngtDOIrUm0vi1WgaRlIYZUgEqGCwHZ17/Z73Y2E5ycG+Cvn92uymRVc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790178680; c=relaxed/simple; bh=YltGBX65BN3apS6Op67TDxRjOTDL3Nv6GkYEJt56dNI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RLXL6x1Khd/S+aVVxTJKQPRFSXbRwN1dtWxNyM0z/07viDKmW1yuTbLzM7/beC21IGjfssPFOGI9lR16HRmTGsuA2Thr4pOXph+BdHu9YgDOlOg20Nh09MUQ6rPxZKvfyv9xeKJUd0XRmqjtY0Xbo3O3FlDGD7ueJ787Sp0CUK0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=m84d6++H; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="m84d6++H" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-8623e5d4279so1654040b3a.1 for ; Wed, 23 Sep 2026 08:51:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790178672; x=1790783472; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xpOXPyZtLg83VF0R6mkL6Bp5HwN6yDRFCZL9glrow7k=; b=m84d6++HkQhbS27vocvK8O41j89M5+ahN34Mtp/mn54clYeSPpI27pS0fOWYO3ZMj2 EJrdl2hun/TsCOnrH8cI3JR/bV0XuHERU+lCkOyzyxmMxZ1a7UWJVmlLFsGjrIWGMxOd h/yVvPfperDXvGzqiW/Y+9HZ3LjKsVeWbTGE06VI1+a4NNMeyIc0aPxyr6SVe2DxsyD3 bxp0iqZLK8qb6UttMpiKmqoYK7kJj5PDoe7nR+RAKSDN2vqtIkBCGj48lWNtWLVH8ARR PEq4TUxxEc4vwQi+SOPY08Ngv1ywOeUqGzgWZkU0HJlgjxgf86e04Pn9sZgFZ+LfkpK0 OMtQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790178672; x=1790783472; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=xpOXPyZtLg83VF0R6mkL6Bp5HwN6yDRFCZL9glrow7k=; b=CW/iE4RaAfzHidhiDTCmeGWE3Mvh0yi15PRrDF5Qr5IWwfLXHKtEADltLMgzSBJ8t1 nC3s588+0bj7LbKPZYVoq9B22+QXP0zwMBxmeGJe3NYVO8dWg8wMhdGVRY7OUtRlPA6H aesBloQR/BeV3rIyKIZXBesok7HMX4pjV4YWpc84FmC0ksFdO9GwtkKwlPJYNchUjl2/ Zjokthd6DFnvlDuvGq4RvWr2AdTQqqIk0EBMjxWjkZidBQ3QVDSkBxbQRYQyaav8EPnG IGYxeh2QLtI2vt9ernkDN+uYXL2KjaXxJxA5Ddc/eJBcTTDhRXJAXdB2RtnXHVkL5Cbb RPAQ== X-Forwarded-Encrypted: i=1; AKwUvBxtU0jvZDk79OozrghwtdNf1RJakzTKLVAuyu+q4BlGTC6YL5H8BYkydt0CrxM93Y1OkSS2kMFtL6fbBA0=@vger.kernel.org X-Gm-Message-State: AFuF++nlhRZmS7FoYQkS5UOrLvUH9lPbLDxnv9rYzwm5IZKLYKBi/uy0 IVccvHKm/q6xkkTReyn99oIs0wyqjXgyOCbdxYVm++jlEJkfyvUEeKkl7yrYqI5uaNb7Mw1Pdin WQEs/Jg== X-Received: from pfbgd10.prod.google.com ([2002:a05:6a00:830a:b0:863:cabd:d30d]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:99a:b0:878:34f8:fb6 with SMTP id d2e1a72fcca58-87d1c9c6e2amr2676193b3a.54.1790178671607; Wed, 23 Sep 2026 08:51:11 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 23 Sep 2026 08:51:06 -0700 In-Reply-To: <20260923155108.1550622-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260923155108.1550622-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260923155108.1550622-2-seanjc@google.com> Subject: [PATCH v2 1/3] KVM: SVM: Add paranoid helper for checking if vCPU is AVIC-addressable From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Naveen N Rao , Atish Patra Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add a helper to check if a vCPU is addressable by AVIC hardware, i.e. has an APIC ID that fits in the physical ID table, and use the more paranoid helper when determining if a vCPU is compatible with AVIC when initializing the vCPU. KVM is supposed to reject vCPU creation if the vCPU's ID is greater than or equal to max_vcpu_ids, i.e. simply checking the architectural maximum *should* suffice. But piecing together why this is safe is unnecessarily difficult, and there is no meaningful downside to being extra cautious. Suggested-by: Naveen N Rao (AMD) Signed-off-by: Sean Christopherson Reviewed-by: Naveen N Rao (AMD) --- arch/x86/kvm/svm/avic.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/avic.c b/arch/x86/kvm/svm/avic.c index 3b037e385523..0e4b5eb6ac82 100644 --- a/arch/x86/kvm/svm/avic.c +++ b/arch/x86/kvm/svm/avic.c @@ -395,6 +395,11 @@ static phys_addr_t avic_get_backing_page_address(struc= t vcpu_svm *svm) return __sme_set(__pa(svm->vcpu.arch.apic->regs)); } =20 +static bool avic_is_addressable_vcpu(struct kvm_vcpu *vcpu) +{ + return vcpu->vcpu_id <=3D __avic_get_max_physical_id(vcpu->kvm, NULL); +} + void avic_init_vmcb(struct vcpu_svm *svm, struct vmcb *vmcb) { struct kvm_svm *kvm_svm =3D to_kvm_svm(svm->vcpu.kvm); @@ -412,7 +417,6 @@ void avic_init_vmcb(struct vcpu_svm *svm, struct vmcb *= vmcb) =20 static int avic_init_backing_page(struct kvm_vcpu *vcpu) { - u32 max_id =3D x2avic_enabled ? x2avic_max_physical_id : AVIC_MAX_PHYSICA= L_ID; struct kvm_svm *kvm_svm =3D to_kvm_svm(vcpu->kvm); struct vcpu_svm *svm =3D to_svm(vcpu); u32 id =3D vcpu->vcpu_id; @@ -425,7 +429,7 @@ static int avic_init_backing_page(struct kvm_vcpu *vcpu) * avic_vcpu_load() expects to be called if and only if the vCPU has * fully initialized AVIC. */ - if (id > max_id) { + if (!avic_is_addressable_vcpu(vcpu)) { kvm_set_apicv_inhibit(vcpu->kvm, APICV_INHIBIT_REASON_PHYSICAL_ID_TOO_BI= G); vcpu->arch.apic->apicv_active =3D false; return 0; --=20 2.55.0.1082.g2b9226bbc0-goog From nobody Thu Sep 24 13:39:03 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4767852B1FE for ; Wed, 23 Sep 2026 15:51:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790178679; cv=none; b=kSuvL7aV7hoAgzdPEXiXBuIC9abQydw/JerSdFAbRFPBbVgVN/wVTphtEQKOdh4HMVrif28C1Nh13bj4epLsVpLY9mN1oZuwYfN2PloXVXpIeGFg4JGP8mOquyCym8aVCqx/KiRSL4RdgKBNHvJCLFAfA5SfHTUGMiYQtw5dhYk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790178679; c=relaxed/simple; bh=hAGeqAtPkGOS41f5bDyMSpg3ysHNF8998MztkXzdvV0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=BGUdrgXNLbq2zNNZU63NTex14vpUoWbSOpFLEOt83BZEucEHuWA+C/W+8Tw+vKMAz7YSrZ9mDVtA9CSOAt5+Lv23va6P7HjgzymkmsR+D7E7V26tmk8mmkf9747L1EZ2ZI0g3TVcTaHNERf6Q6VUU13P86hCt4Dm9S7Drlw/OW0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=aluaDtGt; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="aluaDtGt" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-395543dc382so1132193a91.0 for ; Wed, 23 Sep 2026 08:51:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790178673; x=1790783473; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=BZvXYDcMxG9QzYOllEJznxsL4DUn8KPA1psb/Zru+OQ=; b=aluaDtGtzecMttII5rgAmNOnwBDgPK7j7OheAHVdzhmrLZ92YPieDi3YB9lMyYmep7 RRX8j9DlR5RTiNGe+5u5Ot75jx0554s279+YoqzBdte0gDKNkMk0NXGr6XPblIsJ2cqm NuyjfNlbfJ8WSas5yzJOKKp+Z8vxjZrviJ64PQx33hzEZLxZ6C4rDn3oiIRvNDt7p+S/ GUd8pztChr7V9l3k0BxwoiGbbF4JnhyM+OPIDRBnXG1L61cescoa8/jH62DkwLMF6bNA KAGfZAZiYX898EcCjRlu9uP7rhoaIDD6YOkWX8zI48nHL8qXyf6820amFP7ulUDNF4vn 2gBw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790178673; x=1790783473; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=BZvXYDcMxG9QzYOllEJznxsL4DUn8KPA1psb/Zru+OQ=; b=iKSHEyRMzkGp08SZ802Dab7oCQKU9PBrmIlxQ45zTsSXO10ll/mDgwpQJVPCRD3pAm U8ZYDmC2IFqLfarQHqxNUWlTN9UYJa8SuuALHYfkzYjBS3K2VI6ZheEJy5yVjfTZwhcq k4+qpSgPn2sbL0V7aaD45+UtRSQV9Vvrh6ztvmSLaFqB93IFVmusMmAWyZlwV8xhUlPi pA2Lo0lvh/I425JfuLzf+5+4mds1owaFJV1cbIYBWpz/LUbdROa3+PD6sz7BGZsXcX5y ZUx3zwOlHAkvtvxc5RopE1lrIP420vm8BJMH3NBUvQlvxnSoMQ4jZVWHKOKIEWjX/CPI ll/Q== X-Forwarded-Encrypted: i=1; AKwUvBwsaKZtRwax0+0lyuZFbFuJTS/ubLcG50Tnegt1PEeDX7UkkxEoyVk3oX1zDyOLg7SZ1VkD28wJWWJzQjg=@vger.kernel.org X-Gm-Message-State: AFuF++mP+xk3lOddWIs+r0IxrhW+f87dz72ey4p9NVJH8gf5WaqWgoSC DTuOHB/7MsGd6EOfBa+8ps6idQrhCGGoTZND4a1aLjytzzTMSXOzqdnNeo41QOXbmZBdJWDXmpb 6b5FOAA== X-Received: from pjbkw10.prod.google.com ([2002:a17:90b:220a:b0:3a0:6d58:1c3b]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:2fce:b0:3a0:3881:eabe with SMTP id 98e67ed59e1d1-3a07e4ee868mr2520155a91.5.1790178672821; Wed, 23 Sep 2026 08:51:12 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 23 Sep 2026 08:51:07 -0700 In-Reply-To: <20260923155108.1550622-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260923155108.1550622-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260923155108.1550622-3-seanjc@google.com> Subject: [PATCH v2 2/3] KVM: SVM: Use "is AVIC-addressable" helper to sanity check load()/put() From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Naveen N Rao , Atish Patra Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Use avic_is_addressable_vcpu() instead of open coding a check on the bounds of the allocated table for the sanity checks when loading/putting AVIC state for a vCPU. If KVM botches the allocation, then KVM will already have performed an OOB write in avic_init_backing_page(), i.e. being super paranoid in load()/put() doesn't provide meaningful protection in practice. Cc: Naveen N Rao (AMD) Signed-off-by: Sean Christopherson Reviewed-by: Naveen N Rao (AMD) --- arch/x86/kvm/svm/avic.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/arch/x86/kvm/svm/avic.c b/arch/x86/kvm/svm/avic.c index 0e4b5eb6ac82..4173a30dfe60 100644 --- a/arch/x86/kvm/svm/avic.c +++ b/arch/x86/kvm/svm/avic.c @@ -1049,8 +1049,7 @@ static void __avic_vcpu_load(struct kvm_vcpu *vcpu, i= nt cpu, if (WARN_ON(h_physical_id & ~AVIC_PHYSICAL_ID_ENTRY_HOST_PHYSICAL_ID_MASK= )) return; =20 - if (WARN_ON_ONCE(vcpu->vcpu_id * sizeof(entry) >=3D - PAGE_SIZE << avic_get_physical_id_table_order(vcpu->kvm))) + if (WARN_ON_ONCE(!avic_is_addressable_vcpu(vcpu))) return; =20 /* @@ -1112,8 +1111,7 @@ static void __avic_vcpu_put(struct kvm_vcpu *vcpu, en= um avic_vcpu_action action) =20 lockdep_assert_preemption_disabled(); =20 - if (WARN_ON_ONCE(vcpu->vcpu_id * sizeof(entry) >=3D - PAGE_SIZE << avic_get_physical_id_table_order(vcpu->kvm))) + if (WARN_ON_ONCE(!avic_is_addressable_vcpu(vcpu))) return; =20 /* --=20 2.55.0.1082.g2b9226bbc0-goog From nobody Thu Sep 24 13:39:03 2026 Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3562D39CD1F for ; Wed, 23 Sep 2026 15:51:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790178683; cv=none; b=Z2SPn2EqQQa8w7oHKWlnDsmkyR/tjlIXCV53qe6JeyEuLBIW7KZ60yCszjJ/xir3HT6VOWLtQUPUEv34+uVDUxpG5+3eJfz6sc/U6l0vE4DS1/QIJm1tPeA8pAAYPcIgqtmdM2DSBP7SnBc4Gyrs9EnO/ybmi3LB47rUHAhsmao= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790178683; c=relaxed/simple; bh=Vn7Yb/To97gB1mHdv2b7cq0yxSEzkws7zRDQe0LYJQ8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=rJPKbCuRWVIizEqb1j6Q9HuEit+35ODVtd7QUPePU31S4M4D79rfKCYDeU07LVDvnPxS/6Y/ryIULqb7hRynSfVnKQBmj7a6R4PwnkJftNFbNMHpm/jVDa1Bfd68UNT/77UT4XsaD9l3LITfehxO4y8jCwG66n5b0Fc7xVTyZ5w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=UWFwruHk; arc=none smtp.client-ip=209.85.216.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="UWFwruHk" Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-38f283baf1fso997086a91.3 for ; Wed, 23 Sep 2026 08:51:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790178674; x=1790783474; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cY3L7frn4nkr2uyxD7c5k8nfl5DVj2AlSPH8dpGX6a0=; b=UWFwruHkQ/qAbB2J/x/rne+wpQCtUqZurCMJgaa3gFPSgT6Kg9sFbhut9lINPMiYwI fZ1ZiijcWIPngKtMy+20RgQMFo5iI80/vSGwPqBhfkMbtIfDhWnHicHZl0PFJe9c6Psh VuVeA98KMWZTMOSCQxBRRwA+X7gle7iWd+++Sv6wCR7UYLTpiFhSf0ywCoeMNj6okjfn H6WU8n3EAuYeMtEjjahf3DS1rxNc1IsqNtV9tcZiJ+qIPSMxlaSFm8mQprRMoTi8vP5I dw2BLrwBNw6wWLT1vDM5bQ31dcAFkNhiXBQQC95V7fZ7tVlaCBTsGn3nIZ46T/kWAaMx FR/A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790178674; x=1790783474; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=cY3L7frn4nkr2uyxD7c5k8nfl5DVj2AlSPH8dpGX6a0=; b=KP8WzcySS0682gU4tJRIuQpZ9SsNvoMaWFpPxdXN3EvJGeUn+93Q0L84Gvr1ZtTzMt NM3zIx6/JKurEXfftY5LVObU2aY2R/ZkXDfNUMyvVNPYLxs/Wcag9x4YM5urK9lH3U8R t02oIUDynjau8rkAS283BeNW8TTmr1S394dSZW06Y9JOXyCfjeXkNuIBkSs8gA+O+nwg peRrNGfb64RdFRLOutxN6U33IPk4l5qq8p2SqFLTNIdceh7uHAY+FLadjIAWZCnfcQkL J7huWBUQJiuNF7B+k+cgzwDNFQIVQzUg/QhoO6blh1MDUU99BsAMUPM6bn3QygjDHD93 L0sA== X-Forwarded-Encrypted: i=1; AKwUvBy+YTSRoT8nQLXmGlDhD531VjOl98fGXBVY69MsqhnO21nsHP0E+tgv3UxA22TrvU/Q7YfbDt5hAIPIp7w=@vger.kernel.org X-Gm-Message-State: AFuF++kuh3LVuLE+DflRxOCa0hITWAwaz/uPx9qvNHd3mhBv17eJoaws 5/AaHVepTa1Lc2hgwUUw3p20xijaGC1Rgg3n95zqEPWlSU6Z8HUfd9GiGDevqyMYFtQXp6kwoiX Hg1lWYQ== X-Received: from pjbbh7.prod.google.com ([2002:a17:90b:487:b0:3a0:8315:fa7b]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:2fc8:b0:39e:1c03:14c2 with SMTP id 98e67ed59e1d1-3a07e4e348amr3249729a91.11.1790178673926; Wed, 23 Sep 2026 08:51:13 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 23 Sep 2026 08:51:08 -0700 In-Reply-To: <20260923155108.1550622-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260923155108.1550622-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260923155108.1550622-4-seanjc@google.com> Subject: [PATCH v2 3/3] KVM: SVM: Clear AVIC Physical ID table entry if vCPU creation fails From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Naveen N Rao , Atish Patra Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Naveen N Rao If vCPU creation fails after kvm_arch_vcpu_create(), the AVIC Physical ID table entry corresponding to that vCPU continues to point to the freed APIC backing page which can result in UAF. Address this by clearing out the corresponding AVIC Physical ID table entry in the vcpu_free() callback, similar to the VMX commit b41f2ca6c060 ("KVM: VMX: Fix stale PID-pointer table entry left after vCPU free"). Though unlikely, it is also possible that svm_vcpu_create() itself fails after the AVIC Physical ID table entry has been setup if memory allocation fails in svm_vcpu_alloc_msrpm(). Clear the entry in this path as well. Note: this change depends on commit 97d65b544f48 ("KVM: Check for duplicate vcpu_id as early as possible"), which ensures that a vCPU with a duplicate ID is never created. Otherwise, a valid AVIC Physical ID table entry for an existing vCPU will be cleared. Fixes: 44a95dae1d22 ("KVM: x86: Detect and Initialize AVIC support") Signed-off-by: Naveen N Rao (AMD) Tested-by: Atish Patra [sean: use avic_is_addressable_vcpu()] Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/avic.c | 8 ++++++++ arch/x86/kvm/svm/svm.c | 6 +++++- arch/x86/kvm/svm/svm.h | 1 + 3 files changed, 14 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/svm/avic.c b/arch/x86/kvm/svm/avic.c index 4173a30dfe60..96ca39c0045f 100644 --- a/arch/x86/kvm/svm/avic.c +++ b/arch/x86/kvm/svm/avic.c @@ -889,6 +889,14 @@ int avic_init_vcpu(struct vcpu_svm *svm) return ret; } =20 +void avic_vcpu_free(struct kvm_vcpu *vcpu) +{ + struct kvm_svm *kvm_svm =3D to_kvm_svm(vcpu->kvm); + + if (kvm_svm->avic_physical_id_table && avic_is_addressable_vcpu(vcpu)) + WRITE_ONCE(kvm_svm->avic_physical_id_table[vcpu->vcpu_id], 0); +} + void avic_apicv_post_state_restore(struct kvm_vcpu *vcpu) { avic_handle_dfr_update(vcpu); diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c index 7d59d301e1e5..686e4c560fec 100644 --- a/arch/x86/kvm/svm/svm.c +++ b/arch/x86/kvm/svm/svm.c @@ -1337,7 +1337,7 @@ static int svm_vcpu_create(struct kvm_vcpu *vcpu) svm->msrpm =3D svm_vcpu_alloc_msrpm(); if (!svm->msrpm) { err =3D -ENOMEM; - goto error_free_sev; + goto error_free_avic; } =20 svm->x2avic_msrs_intercepted =3D true; @@ -1351,6 +1351,8 @@ static int svm_vcpu_create(struct kvm_vcpu *vcpu) =20 return 0; =20 +error_free_avic: + avic_vcpu_free(vcpu); error_free_sev: sev_free_vcpu(vcpu); error_free_vmcb_page: @@ -1365,6 +1367,8 @@ static void svm_vcpu_free(struct kvm_vcpu *vcpu) =20 WARN_ON_ONCE(!list_empty(&svm->ir_list)); =20 + avic_vcpu_free(vcpu); + svm_leave_nested(vcpu); svm_free_nested(svm); =20 diff --git a/arch/x86/kvm/svm/svm.h b/arch/x86/kvm/svm/svm.h index e958943b8162..790bd96a9791 100644 --- a/arch/x86/kvm/svm/svm.h +++ b/arch/x86/kvm/svm/svm.h @@ -954,6 +954,7 @@ void avic_init_vmcb(struct vcpu_svm *svm, struct vmcb *= vmcb); int avic_incomplete_ipi_interception(struct kvm_vcpu *vcpu); int avic_unaccelerated_access_interception(struct kvm_vcpu *vcpu); int avic_init_vcpu(struct vcpu_svm *svm); +void avic_vcpu_free(struct kvm_vcpu *vcpu); void avic_vcpu_load(struct kvm_vcpu *vcpu, int cpu); void avic_vcpu_put(struct kvm_vcpu *vcpu); void avic_apicv_post_state_restore(struct kvm_vcpu *vcpu); --=20 2.55.0.1082.g2b9226bbc0-goog