From: sashiko-bot@kernel.org
To: "Sean Christopherson" <seanjc@google.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload
Date: Wed, 30 Sep 2026 01:28:08 +0000 [thread overview]
Message-ID: <20260930012809.331EB1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930011313.3197688-6-seanjc@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] kvm/x86: host DoS via WARN_ON_ONCE in kvm_deliver_exception_payload
--
commit 55e3dfb3c54d9318de7a4a9b55c84a0a9acf4aa2
Author: Sean Christopherson <seanjc@google.com>
KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload
This commit adds a WARN_ON_ONCE to kvm_deliver_exception_payload() to assert
that fixed-1 bits in DR6 are already set when delivering a #DB payload. It
also switches to using kvm_get_dr6_fixed_1() for the check.
> diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> index 99518e3265b45..5b3918a4ed521 100644
> --- a/arch/x86/kvm/x86.c
> +++ b/arch/x86/kvm/x86.c
[ ... ]
> @@ -440,8 +442,10 @@ void kvm_deliver_exception_payload(struct kvm_vcpu *vcpu,
> * breakpoint), it is reserved and must be zero in DR6.
> */
> vcpu->arch.dr6 &= ~BIT(12);
> - vcpu->arch.dr6 |= DR6_FIXED_1;
> + if (WARN_ON_ONCE((vcpu->arch.dr6 & dr6_fixed_1) != dr6_fixed_1))
> + vcpu->arch.dr6 |= dr6_fixed_1;
[Severity: High]
Can an unprivileged host-userspace process trigger this warning in
kvm_deliver_exception_payload() in arch/x86/kvm/x86.c by injecting a
malformed dr6 state?
If host-userspace invokes the kvm_vcpu_ioctl_x86_set_debugregs() via the
KVM_SET_DEBUGREGS ioctl in arch/x86/kvm/regs.c with dbgregs.dr6 = 0, it
clears all fixed-1 bits in vcpu->arch.dr6, since kvm_dr6_valid() only
validates the upper 32 bits.
Then, if it invokes kvm_vcpu_ioctl_x86_set_vcpu_events() in
arch/x86/kvm/x86.c via the KVM_SET_VCPU_EVENTS ioctl to queue a pending
#DB exception with an unchecked payload and runs the VCPU via KVM_RUN,
kvm_deliver_exception_payload() will evaluate this newly added
WARN_ON_ONCE before the fixed-1 bits are restored.
On systems with panic_on_warn=1, could this result in a host kernel panic
and a denial of service?
> break;
> + }
> case PF_VECTOR:
> vcpu->arch.cr2 = ex->payload;
> break;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930011313.3197688-1-seanjc@google.com?part=5
next prev parent reply other threads:[~2026-09-30 1:28 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 1:13 [PATCH v5 00/12] KVM: x86: Bus Lock Detect fixes and SVM support Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 01/12] KVM: x86: Preserve DR6.BLD (Bus Lock Detect) when delivering #DB payload Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 02/12] KVM: x86: Rename kvm_dr6_fixed() => kvm_get_dr6_fixed_1() Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 03/12] KVM: Return an "unsigned long", not "u64" for the fixed-1 DR6 bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 04/12] KVM: x86: Force fixed-1 bits in DR6 after synchronizing with hardware Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload Sean Christopherson
2026-09-30 1:28 ` sashiko-bot [this message]
2026-09-30 12:59 ` Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 06/12] KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse Sean Christopherson
2026-09-30 1:28 ` sashiko-bot
2026-09-30 1:13 ` [PATCH v5 07/12] KVM: SVM: Add helper to query if LBR virtualization needs to be enabled Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 08/12] KVM: nSVM: Disable LBRV in nested control cache when unsupported Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 09/12] KVM: nSVM: Open code check on LBR virtualization being enabled in vmcb12 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 10/12] KVM: nSVM: Don't assume all active-low bits DR6 are fixed-1 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 11/12] KVM: SVM: Add a vCPU-aware helper to get supported DEBUGCTL bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 12/12] KVM: SVM: Add support for virtualizating Bus Lock Detect Sean Christopherson
2026-09-30 1:36 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930012809.331EB1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=seanjc@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox