From: Sean Christopherson <seanjc@google.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload
Date: Wed, 30 Sep 2026 05:59:52 -0700 [thread overview]
Message-ID: <ar0HyDZ_mUqUK5cn@google.com> (raw)
In-Reply-To: <20260930012809.331EB1F000FF@smtp.kernel.org>
On Wed, Sep 30, 2026, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] kvm/x86: host DoS via WARN_ON_ONCE in kvm_deliver_exception_payload
> --
>
> commit 55e3dfb3c54d9318de7a4a9b55c84a0a9acf4aa2
> Author: Sean Christopherson <seanjc@google.com>
>
> KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload
>
> This commit adds a WARN_ON_ONCE to kvm_deliver_exception_payload() to assert
> that fixed-1 bits in DR6 are already set when delivering a #DB payload. It
> also switches to using kvm_get_dr6_fixed_1() for the check.
>
> > diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> > index 99518e3265b45..5b3918a4ed521 100644
> > --- a/arch/x86/kvm/x86.c
> > +++ b/arch/x86/kvm/x86.c
> [ ... ]
> > @@ -440,8 +442,10 @@ void kvm_deliver_exception_payload(struct kvm_vcpu *vcpu,
> > * breakpoint), it is reserved and must be zero in DR6.
> > */
> > vcpu->arch.dr6 &= ~BIT(12);
> > - vcpu->arch.dr6 |= DR6_FIXED_1;
> > + if (WARN_ON_ONCE((vcpu->arch.dr6 & dr6_fixed_1) != dr6_fixed_1))
> > + vcpu->arch.dr6 |= dr6_fixed_1;
>
> [Severity: High]
> Can an unprivileged host-userspace process trigger this warning in
> kvm_deliver_exception_payload() in arch/x86/kvm/x86.c by injecting a
> malformed dr6 state?
>
> If host-userspace invokes the kvm_vcpu_ioctl_x86_set_debugregs() via the
> KVM_SET_DEBUGREGS ioctl in arch/x86/kvm/regs.c with dbgregs.dr6 = 0, it
> clears all fixed-1 bits in vcpu->arch.dr6, since kvm_dr6_valid() only
> validates the upper 32 bits.
Drat. I had reservations about adding the sanity check even before Sashiko
chimed in, so I'll just drop it.
>
> Then, if it invokes kvm_vcpu_ioctl_x86_set_vcpu_events() in
> arch/x86/kvm/x86.c via the KVM_SET_VCPU_EVENTS ioctl to queue a pending
> #DB exception with an unchecked payload and runs the VCPU via KVM_RUN,
> kvm_deliver_exception_payload() will evaluate this newly added
> WARN_ON_ONCE before the fixed-1 bits are restored.
>
> On systems with panic_on_warn=1, could this result in a host kernel panic
> and a denial of service?
>
> > break;
> > + }
> > case PF_VECTOR:
> > vcpu->arch.cr2 = ex->payload;
> > break;
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20260930011313.3197688-1-seanjc@google.com?part=5
next prev parent reply other threads:[~2026-09-30 13:00 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 1:13 [PATCH v5 00/12] KVM: x86: Bus Lock Detect fixes and SVM support Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 01/12] KVM: x86: Preserve DR6.BLD (Bus Lock Detect) when delivering #DB payload Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 02/12] KVM: x86: Rename kvm_dr6_fixed() => kvm_get_dr6_fixed_1() Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 03/12] KVM: Return an "unsigned long", not "u64" for the fixed-1 DR6 bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 04/12] KVM: x86: Force fixed-1 bits in DR6 after synchronizing with hardware Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload Sean Christopherson
2026-09-30 1:28 ` sashiko-bot
2026-09-30 12:59 ` Sean Christopherson [this message]
2026-09-30 1:13 ` [PATCH v5 06/12] KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse Sean Christopherson
2026-09-30 1:28 ` sashiko-bot
2026-09-30 1:13 ` [PATCH v5 07/12] KVM: SVM: Add helper to query if LBR virtualization needs to be enabled Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 08/12] KVM: nSVM: Disable LBRV in nested control cache when unsupported Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 09/12] KVM: nSVM: Open code check on LBR virtualization being enabled in vmcb12 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 10/12] KVM: nSVM: Don't assume all active-low bits DR6 are fixed-1 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 11/12] KVM: SVM: Add a vCPU-aware helper to get supported DEBUGCTL bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 12/12] KVM: SVM: Add support for virtualizating Bus Lock Detect Sean Christopherson
2026-09-30 1:36 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar0HyDZ_mUqUK5cn@google.com \
--to=seanjc@google.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox