From: sashiko-bot@kernel.org
To: "Paolo Bonzini" <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH 05/11] KVM: SVM: Use the active VMCB's MSR bitmap when checking if MSR is intercepted
Date: Sat, 26 Sep 2026 05:42:44 +0000 [thread overview]
Message-ID: <20260926054245.063B41F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260926053253.195597-6-pbonzini@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] kvm: svm: invalid pointer dereference in msr_write_intercepted due to SME/SEV C-bit
--
commit 043abbaa7ab3cef236605eca71fa3da8b7711f0e
Author: Sean Christopherson <seanjc@google.com>
KVM: SVM: Use the active VMCB's MSR bitmap when checking if MSR is intercepted
This commit modifies KVM to use the MSR permission bitmap of the active VMCB
instead of maintaining separate tracking logic. It dynamically calculates the
virtual address of the bitmap from the physical address stored in the VMCB
control area using __va().
Message-ID: <20260826195833.844526-1-seanjc@google.com>
> diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
> index f4f488328ea42..1f279cd91ecfb 100644
> --- a/arch/x86/kvm/svm/svm.c
> +++ b/arch/x86/kvm/svm/svm.c
> @@ -673,16 +673,7 @@ static void clr_dr_intercepts(struct vcpu_svm *svm)
>
> static bool msr_write_intercepted(struct vcpu_svm *svm, u32 msr)
> {
[ ... ]
> - void *msrpm = is_guest_mode(&svm->vcpu) ? svm->nested.msrpm : svm->msrpm;
> + void *msrpm = __va(svm->vmcb->control.msrpm_base_pa);
[Severity: Critical]
Does this introduce an invalid pointer dereference when SME or SEV is active?
When Secure Memory Encryption (SME) or Secure Encrypted Virtualization (SEV)
is enabled, physical addresses programmed into hardware structures must
include the encryption bit (C-bit). KVM enforces this by setting the bit
when populating svm->vmcb->control.msrpm_base_pa.
Since __va() on x86 directly adds PAGE_OFFSET to the physical address
without masking out the encryption C-bit, passing the raw physical address
here appears to create an out-of-bounds virtual address. When
svm_test_msr_bitmap_write() immediately dereferences this address, won't
it cause a host panic via a kernel page fault (#PF or #GP)?
Because msr_write_intercepted() is called during VM execution paths, could
a local user with /dev/kvm privileges trigger this to cause a denial of
service on SME/SEV-enabled hardware?
(Note: This issue appears to remain unfixed in the final state of the patch
series at commit 497a001eb419947b).
>
> return svm_test_msr_bitmap_write(msrpm, msr);
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260926053253.195597-1-pbonzini@redhat.com?part=5
next prev parent reply other threads:[~2026-09-26 5:42 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 5:32 [PATCH 00/11] KVM: fix issues with stale control fields Paolo Bonzini
2026-09-26 5:32 ` [PATCH 01/11] KVM: SVM: Preserve TLB control (i.e. pending TLB flush) on failed VMRUN Paolo Bonzini
2026-09-26 5:32 ` [PATCH 02/11] KVM: SVM: Update control fields on #VMEXIT if and only if VMRUN succeeded Paolo Bonzini
2026-09-26 5:32 ` [PATCH 03/11] KVM: SVM: Don't mark ASID fields as dirty when setting control.tlb_ctl Paolo Bonzini
2026-09-26 5:32 ` [PATCH 04/11] KVM: SVM: Sync guest's PERF_CNTR_GLOBAL_CTL from h/w only on successful VMRUN Paolo Bonzini
2026-09-26 5:32 ` [PATCH 05/11] KVM: SVM: Use the active VMCB's MSR bitmap when checking if MSR is intercepted Paolo Bonzini
2026-09-26 5:42 ` sashiko-bot [this message]
2026-09-26 5:32 ` [PATCH 06/11] KVM: nVMX: Force MSR bitmap refresh if runtime eVMCS controls are modified Paolo Bonzini
2026-09-26 5:32 ` [PATCH 07/11] KVM: selftests: Add x2APIC MSR test for inhibiting APICv while nested Paolo Bonzini
2026-09-26 5:32 ` [PATCH 08/11] KVM: selftests: Run the nested x2APIC with and without APICv being inhibited in L2 Paolo Bonzini
2026-09-26 5:32 ` [PATCH 09/11] KVM: selftests: Verify that L0's TPR doesn't get clobbered Paolo Bonzini
2026-09-26 5:42 ` sashiko-bot
2026-09-26 5:32 ` [PATCH 10/11] KVM: selftests: Extend nested x2APIC test to validate disabling x2APIC virt Paolo Bonzini
2026-09-26 5:46 ` sashiko-bot
2026-09-26 5:32 ` [PATCH 11/11] KVM: selftests: Extend nested x2APIC test to validate using eVMCS for vmcs12 Paolo Bonzini
2026-09-26 6:11 ` [PATCH 00/11] KVM: fix issues with stale control fields Paolo Bonzini
2026-09-28 17:01 ` Sean Christopherson
2026-09-26 6:12 ` Paolo Bonzini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926054245.063B41F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox