From: sashiko-bot@kernel.org
To: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
Cc: "Marc Zyngier" <maz@kernel.org>,
kvmarm@lists.linux.dev, "Oliver Upton" <oupton@kernel.org>
Subject: Re: [PATCH v3 2/2] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, teardown race
Date: Tue, 01 Sep 2026 17:46:39 +0000 [thread overview]
Message-ID: <20260901174639.CE9A21F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260901-kvm-arm-nested-virt-fix-v3-2-b154676f7e4c@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Concurrent VM teardown frees the `kvm->arch.nested_mmus` array without holding `kvm->mmu_lock`, causing a Use-After-Free when `kvm_nested_s2_unmap`, `kvm_nested_s2_wp`, or `kvm_nested_s2_flush` iterate over the array.
--
commit 6d817ae312afc7a3c0a4cae55f93ea78c14d26e1
Author: Lorenzo Stoakes (ARM) <ljs@kernel.org>
KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, teardown race
This commit fixes a NULL pointer dereference caused by concurrent stage 2
teardown racing with MMU notifiers by wrapping VNCR IPA invalidation in a
new helper that checks for a NULL page table pointer.
> diff --git a/arch/arm64/kvm/nested.c b/arch/arm64/kvm/nested.c
> index 17123f0b6daba..f69722e1592a5 100644
> --- a/arch/arm64/kvm/nested.c
> +++ b/arch/arm64/kvm/nested.c
[ ... ]
> @@ -1295,7 +1306,7 @@ void kvm_nested_s2_unmap(struct kvm *kvm, bool may_block)
> kvm_stage2_unmap_range(mmu, 0, kvm_phys_size(mmu), may_block);
[Severity: High]
This is a pre-existing issue, but since this patch explicitly deals with the
race between kvm_arch_flush_shadow_all() and MMU notifiers dropping the
mmu_lock, is there a Use-After-Free risk with kvm->arch.nested_mmus here?
If kvm_stage2_unmap_range() ends up calling stage2_apply_range() which
drops kvm->mmu_lock, kvm_arch_flush_shadow_all() can proceed to tear
down the nested MMUs.
In arch/arm64/kvm/nested.c:kvm_arch_flush_shadow_all():
kvfree(kvm->arch.nested_mmus);
kvm->arch.nested_mmus = NULL;
kvm->arch.nested_mmus_size = 0;
This kvfree() happens without holding kvm->mmu_lock.
When the MMU notifier path in kvm_nested_s2_unmap() reacquires the lock
and continues, the mmu pointer (which points into the now-freed
kvm->arch.nested_mmus array) is completely dangling.
For example, in arch/arm64/kvm/mmu.c:stage2_apply_range():
do {
struct kvm_pgtable *pgt = mmu->pgt;
...
Can this dereference of mmu->pgt cause memory corruption or crashes if the
underlying array has been freed by a concurrent VM teardown?
> }
>
> - kvm_invalidate_vncr_ipa(kvm, 0, BIT(kvm->arch.mmu.pgt->ia_bits));
> + kvm_invalidate_vncr_ipa_all(kvm);
> }
>
> void kvm_nested_s2_flush(struct kvm *kvm)
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260901-kvm-arm-nested-virt-fix-v3-0-b154676f7e4c@kernel.org?part=2
next prev parent reply other threads:[~2026-09-01 17:46 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 17:28 [PATCH v3 0/2] KVM: arm64: Fix spurious warn, null ptr deref on S2 teardown race Lorenzo Stoakes (ARM)
2026-09-01 17:28 ` [PATCH v3 1/2] KVM: arm64: Fix spurious warning for benign stage 2 " Lorenzo Stoakes (ARM)
2026-09-01 17:46 ` sashiko-bot
2026-09-01 17:29 ` [PATCH v3 2/2] KVM: arm64: nv: Fix null ptr deref on nested wp/unmap, " Lorenzo Stoakes (ARM)
2026-09-01 17:46 ` sashiko-bot [this message]
2026-09-11 8:12 ` Jonathan Davies
2026-09-11 8:44 ` Lorenzo Stoakes (ARM)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260901174639.CE9A21F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=ljs@kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.