Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Sean Christopherson <seanjc@google.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload
Date: Wed, 30 Sep 2026 05:59:52 -0700	[thread overview]
Message-ID: <ar0HyDZ_mUqUK5cn@google.com> (raw)
In-Reply-To: <20260930012809.331EB1F000FF@smtp.kernel.org>

On Wed, Sep 30, 2026, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] kvm/x86: host DoS via WARN_ON_ONCE in kvm_deliver_exception_payload
> --
> 
> commit 55e3dfb3c54d9318de7a4a9b55c84a0a9acf4aa2
> Author: Sean Christopherson <seanjc@google.com>
> 
> KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload
> 
> This commit adds a WARN_ON_ONCE to kvm_deliver_exception_payload() to assert
> that fixed-1 bits in DR6 are already set when delivering a #DB payload. It
> also switches to using kvm_get_dr6_fixed_1() for the check.
> 
> > diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> > index 99518e3265b45..5b3918a4ed521 100644
> > --- a/arch/x86/kvm/x86.c
> > +++ b/arch/x86/kvm/x86.c
> [ ... ]
> > @@ -440,8 +442,10 @@ void kvm_deliver_exception_payload(struct kvm_vcpu *vcpu,
> >  		 * breakpoint), it is reserved and must be zero in DR6.
> >  		 */
> >  		vcpu->arch.dr6 &= ~BIT(12);
> > -		vcpu->arch.dr6 |= DR6_FIXED_1;
> > +		if (WARN_ON_ONCE((vcpu->arch.dr6 & dr6_fixed_1) != dr6_fixed_1))
> > +			vcpu->arch.dr6 |= dr6_fixed_1;
> 
> [Severity: High]
> Can an unprivileged host-userspace process trigger this warning in
> kvm_deliver_exception_payload() in arch/x86/kvm/x86.c by injecting a
> malformed dr6 state?
> 
> If host-userspace invokes the kvm_vcpu_ioctl_x86_set_debugregs() via the
> KVM_SET_DEBUGREGS ioctl in arch/x86/kvm/regs.c with dbgregs.dr6 = 0, it
> clears all fixed-1 bits in vcpu->arch.dr6, since kvm_dr6_valid() only
> validates the upper 32 bits.

Drat.  I had reservations about adding the sanity check even before Sashiko
chimed in, so I'll just drop it.

> 
> Then, if it invokes kvm_vcpu_ioctl_x86_set_vcpu_events() in
> arch/x86/kvm/x86.c via the KVM_SET_VCPU_EVENTS ioctl to queue a pending
> #DB exception with an unchecked payload and runs the VCPU via KVM_RUN,
> kvm_deliver_exception_payload() will evaluate this newly added
> WARN_ON_ONCE before the fixed-1 bits are restored.
> 
> On systems with panic_on_warn=1, could this result in a host kernel panic
> and a denial of service?
> 
> >  		break;
> > +	}
> >  	case PF_VECTOR:
> >  		vcpu->arch.cr2 = ex->payload;
> >  		break;
> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/20260930011313.3197688-1-seanjc@google.com?part=5

  reply	other threads:[~2026-09-30 13:00 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  1:13 [PATCH v5 00/12] KVM: x86: Bus Lock Detect fixes and SVM support Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 01/12] KVM: x86: Preserve DR6.BLD (Bus Lock Detect) when delivering #DB payload Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 02/12] KVM: x86: Rename kvm_dr6_fixed() => kvm_get_dr6_fixed_1() Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 03/12] KVM: Return an "unsigned long", not "u64" for the fixed-1 DR6 bits Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 04/12] KVM: x86: Force fixed-1 bits in DR6 after synchronizing with hardware Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload Sean Christopherson
2026-09-30  1:28   ` sashiko-bot
2026-09-30 12:59     ` Sean Christopherson [this message]
2026-09-30  1:13 ` [PATCH v5 06/12] KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse Sean Christopherson
2026-09-30  1:28   ` sashiko-bot
2026-09-30  1:13 ` [PATCH v5 07/12] KVM: SVM: Add helper to query if LBR virtualization needs to be enabled Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 08/12] KVM: nSVM: Disable LBRV in nested control cache when unsupported Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 09/12] KVM: nSVM: Open code check on LBR virtualization being enabled in vmcb12 Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 10/12] KVM: nSVM: Don't assume all active-low bits DR6 are fixed-1 Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 11/12] KVM: SVM: Add a vCPU-aware helper to get supported DEBUGCTL bits Sean Christopherson
2026-09-30  1:13 ` [PATCH v5 12/12] KVM: SVM: Add support for virtualizating Bus Lock Detect Sean Christopherson
2026-09-30  1:36   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ar0HyDZ_mUqUK5cn@google.com \
    --to=seanjc@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox