From: sashiko-bot@kernel.org
To: "Sean Christopherson" <seanjc@google.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v5 06/12] KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse
Date: Wed, 30 Sep 2026 01:28:02 +0000 [thread overview]
Message-ID: <20260930012803.7E46E1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930011313.3197688-7-seanjc@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] x86/kvm: Host-triggerable WARN_ON_ONCE in kvm_deliver_exception_payload()
--
commit 48eae248dd35f5828c9a4c63f37a8c7de96050db
Author: Sean Christopherson <seanjc@google.com>
KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse
This commit drops the hardcoded DR6_FIXED_1 macro to force all references
to fixed-1 bits to use the vCPU-aware helper. It also rewords the comment
about DR6_ACTIVE_LOW to explain why treating fixed-1 bits as active-low is
correct. No functional change is intended.
> diff --git a/arch/x86/kvm/regs.c b/arch/x86/kvm/regs.c
> index db43ade8ceb10..0c76cf17e8847 100644
> --- a/arch/x86/kvm/regs.c
> +++ b/arch/x86/kvm/regs.c
> @@ -774,7 +774,7 @@ EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_update_dr7);
>
> unsigned long kvm_get_dr6_fixed_1(struct kvm_vcpu *vcpu)
> {
> - unsigned long fixed = DR6_FIXED_1;
> + unsigned long fixed = DR6_ACTIVE_LOW & ~DR6_VOLATILE;
>
> if (!guest_cpu_cap_has(vcpu, X86_FEATURE_RTM))
> fixed |= DR6_RTM;
[Severity: High]
Does this code allow an unvalidated exception payload to trigger a host
WARN_ON_ONCE?
Looking at kvm_vcpu_ioctl_x86_set_vcpu_events(), it accepts an unvalidated
exception payload from host userspace into the vcpu state:
arch/x86/kvm/x86.c:kvm_vcpu_ioctl_x86_set_vcpu_events()
vcpu->arch.exception.payload = events->exception_payload;
When KVM later processes this exception in kvm_deliver_exception_payload(),
it computes dr6_fixed_1 using kvm_get_dr6_fixed_1() and then clears any
active-low bits present in the payload from vcpu->arch.dr6:
arch/x86/kvm/x86.c:kvm_deliver_exception_payload()
vcpu->arch.dr6 &= ~(ex->payload & DR6_ACTIVE_LOW);
If a malicious payload sets active-low fixed-1 bits (like DR6_RTM when it is
unsupported by the guest), those bits are improperly cleared from the guest's
DR6 register.
This causes the subsequent check to fail and trigger the warning:
arch/x86/kvm/x86.c:kvm_deliver_exception_payload()
if (WARN_ON_ONCE((vcpu->arch.dr6 & dr6_fixed_1) != dr6_fixed_1))
vcpu->arch.dr6 |= dr6_fixed_1;
Since panic_on_warn could be enabled, could an unprivileged host userspace
process use this regression to trigger a host-side Denial of Service?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930011313.3197688-1-seanjc@google.com?part=6
next prev parent reply other threads:[~2026-09-30 1:28 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 1:13 [PATCH v5 00/12] KVM: x86: Bus Lock Detect fixes and SVM support Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 01/12] KVM: x86: Preserve DR6.BLD (Bus Lock Detect) when delivering #DB payload Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 02/12] KVM: x86: Rename kvm_dr6_fixed() => kvm_get_dr6_fixed_1() Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 03/12] KVM: Return an "unsigned long", not "u64" for the fixed-1 DR6 bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 04/12] KVM: x86: Force fixed-1 bits in DR6 after synchronizing with hardware Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload Sean Christopherson
2026-09-30 1:28 ` sashiko-bot
2026-09-30 12:59 ` Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 06/12] KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse Sean Christopherson
2026-09-30 1:28 ` sashiko-bot [this message]
2026-09-30 1:13 ` [PATCH v5 07/12] KVM: SVM: Add helper to query if LBR virtualization needs to be enabled Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 08/12] KVM: nSVM: Disable LBRV in nested control cache when unsupported Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 09/12] KVM: nSVM: Open code check on LBR virtualization being enabled in vmcb12 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 10/12] KVM: nSVM: Don't assume all active-low bits DR6 are fixed-1 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 11/12] KVM: SVM: Add a vCPU-aware helper to get supported DEBUGCTL bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 12/12] KVM: SVM: Add support for virtualizating Bus Lock Detect Sean Christopherson
2026-09-30 1:36 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930012803.7E46E1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=seanjc@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox