From: sashiko-bot@kernel.org
To: "Vincent Donnefort" <vdonnefort@google.com>
Cc: kvmarm@lists.linux.dev, "Oliver Upton" <oupton@kernel.org>,
"Marc Zyngier" <maz@kernel.org>
Subject: Re: [PATCH v3 11/17] KVM: arm64: Filter out non-kernel addresses in kern_hyp_va
Date: Mon, 20 Jul 2026 17:28:23 +0000 [thread overview]
Message-ID: <20260720172824.2E5021F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260720171513.1415357-12-vdonnefort@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Short-circuiting `kern_hyp_va()` for addresses below `PAGE_OFFSET` allows a malicious untrusted host to bypass EL2 address translation and access hypervisor-private memory.
--
--- Patch [11]: [PATCH v3 11/17] KVM: arm64: Filter out non-kernel addresses in kern_hyp_va ---
commit 9a2b59e70629aff87b63154ca5dea88e30d5381e
Author: Vincent Donnefort <vdonnefort@google.com>
KVM: arm64: Filter out non-kernel addresses in kern_hyp_va
This commit attempts to make kern_hyp_va() idempotent for non-TTBR1
addresses by short-circuiting the mask-and-tag operation if the address
is below PAGE_OFFSET. The intention is to handle hypervisor linear space
pointers correctly without mangling hypervisor private range addresses.
> diff --git a/arch/arm64/include/asm/kvm_mmu.h b/arch/arm64/include/asm/kvm_mmu.h
> --- a/arch/arm64/include/asm/kvm_mmu.h
> +++ b/arch/arm64/include/asm/kvm_mmu.h
> @@ -126,6 +126,9 @@ static __always_inline unsigned long __kern_hyp_va(unsigned long v)
> * replace the instructions with `nop`s.
> */
> #ifndef __KVM_VHE_HYPERVISOR__
> + if (!is_ttbr1_addr(v))
> + return v;
> +
[Severity: Critical]
Does this short-circuit allow an untrusted host to bypass address translation
and access hypervisor-private memory?
In a pKVM environment, if the host issues a hypercall in the always-on band
and passes a forged pointer corresponding to an EL2 private virtual address,
is_ttbr1_addr() will evaluate to false because the forged address is below
PAGE_OFFSET.
As a result, kern_hyp_va() returns the forged address unmodified, completely
bypassing the mask-and-tag translation. Could this allow the host to trick
the hypervisor into reading or writing EL2 private structures by directly
dereferencing the returned pointer?
> asm volatile(ALTERNATIVE_CB("and %0, %0, #1\n" /* mask with va_mask */
> "ror %0, %0, #1\n" /* rotate to the first tag bit */
> "add %0, %0, #0\n" /* insert the low 12 bits of the tag */
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260720171513.1415357-1-vdonnefort@google.com?part=11
next prev parent reply other threads:[~2026-07-20 17:28 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 17:14 [PATCH v3 00/17] KVM: arm64: Introduce pKVM hypervisor heap allocator Vincent Donnefort
2026-07-20 17:14 ` [PATCH v3 01/17] KVM: arm64: Add pkvm_private_va_range_pa Vincent Donnefort
2026-07-20 17:25 ` sashiko-bot
2026-07-20 17:14 ` [PATCH v3 02/17] KVM: arm64: Add pkvm_remove_mappings Vincent Donnefort
2026-07-20 17:27 ` sashiko-bot
2026-07-20 17:14 ` [PATCH v3 03/17] KVM: arm64: Add pkvm_map_private_va_range Vincent Donnefort
2026-07-20 17:29 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 04/17] KVM: arm64: Add a heap allocator for the pKVM hyp Vincent Donnefort
2026-07-20 17:26 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 05/17] KVM: arm64: Allow kvm_hyp_memcache usage outside of stage-2 Vincent Donnefort
2026-07-20 17:15 ` [PATCH v3 06/17] KVM: arm64: Add pkvm_hyp_req infrastructure Vincent Donnefort
2026-07-20 17:15 ` [PATCH v3 07/17] KVM: arm64: Add PKVM_HYP_REQ_HYP_ALLOC request Vincent Donnefort
2026-07-20 17:36 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 08/17] KVM: arm64: Add reclaim interface for the pKVM heap alloc Vincent Donnefort
2026-07-20 17:32 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 09/17] KVM: arm64: Add selftests for the pKVM heap allocator Vincent Donnefort
2026-07-20 17:31 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 10/17] KVM: arm64: Add a shrinker for pKVM Vincent Donnefort
2026-07-20 17:15 ` [PATCH v3 11/17] KVM: arm64: Filter out non-kernel addresses in kern_hyp_va Vincent Donnefort
2026-07-20 17:28 ` sashiko-bot [this message]
2026-07-20 17:15 ` [PATCH v3 12/17] KVM: arm64: Move hyp_vm refcount into the structure Vincent Donnefort
2026-07-20 17:15 ` [PATCH v3 13/17] KVM: arm64: Alloc pkvm_hyp_vm using pKVM heap allocator Vincent Donnefort
2026-07-20 17:44 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 14/17] KVM: arm64: Alloc pkvm_hyp_vcpu " Vincent Donnefort
2026-07-20 17:41 ` sashiko-bot
2026-07-20 17:15 ` [PATCH v3 15/17] KVM: arm64: Reject hyp trace descriptors with fewer CPUs than hyp_nr_cpus Vincent Donnefort
2026-07-20 17:15 ` [PATCH v3 16/17] KVM: arm64: Reject hyp trace descriptors with fewer than 3 pages Vincent Donnefort
2026-07-20 17:15 ` [PATCH v3 17/17] KVM: arm64: Alloc simple_buffer_page using pKVM hyp allocator Vincent Donnefort
2026-07-20 17:47 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720172824.2E5021F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vdonnefort@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.