Linux IOMMU Development
 help / color / mirror / Atom feed
From: Baolu Lu <baolu.lu@linux.intel.com>
To: Dave Hansen <dave.hansen@intel.com>,
	Joerg Roedel <joro@8bytes.org>, Will Deacon <will@kernel.org>,
	Robin Murphy <robin.murphy@arm.com>,
	Kevin Tian <kevin.tian@intel.com>,
	Jason Gunthorpe <jgg@nvidia.com>, Jann Horn <jannh@google.com>,
	Vasant Hegde <vasant.hegde@amd.com>,
	Alistair Popple <apopple@nvidia.com>,
	Peter Zijlstra <peterz@infradead.org>,
	Uladzislau Rezki <urezki@gmail.com>,
	Jean-Philippe Brucker <jean-philippe@linaro.org>,
	Andy Lutomirski <luto@kernel.org>,
	"Tested-by : Yi Lai" <yi1.lai@intel.com>
Cc: iommu@lists.linux.dev, security@kernel.org,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: Re: [PATCH v2 1/1] iommu/sva: Invalidate KVA range on kernel TLB flush
Date: Thu, 10 Jul 2025 10:14:57 +0800	[thread overview]
Message-ID: <228cd2c9-b781-4505-8b54-42dab03f3650@linux.intel.com> (raw)
In-Reply-To: <ee7585bd-d87c-4f93-9c8e-b8c1d649cdfe@intel.com>

On 7/9/25 23:29, Dave Hansen wrote:
> On 7/8/25 23:28, Lu Baolu wrote:
>> Modern IOMMUs often cache page table entries to optimize walk performance,
>> even for intermediate page table levels. If kernel page table mappings are
>> changed (e.g., by vfree()), but the IOMMU's internal caches retain stale
>> entries, Use-After-Free (UAF) vulnerability condition arises. If these
>> freed page table pages are reallocated for a different purpose, potentially
>> by an attacker, the IOMMU could misinterpret the new data as valid page
>> table entries. This allows the IOMMU to walk into attacker-controlled
>> memory, leading to arbitrary physical memory DMA access or privilege
>> escalation.
> 
> The approach here is certainly conservative and simple. It's also not
> going to cause big problems on systems without fancy IOMMUs.
> 
> But I am a _bit_ worried that it's _too_ conservative. The changelog
> talks about page table page freeing, but the actual code:
> 
>> @@ -1540,6 +1541,7 @@ void flush_tlb_kernel_range(unsigned long start, unsigned long end)
>>   		kernel_tlb_flush_range(info);
>>   
>>   	put_flush_tlb_info();
>> +	iommu_sva_invalidate_kva_range(start, end);
>>   }
> 
> is in a very generic TLB flushing spot that's used for a lot more than
> just freeing page tables.
> 
> If the problem is truly limited to freeing page tables, it needs to be
> commented appropriately.

Yeah, good comments. It should not be limited to freeing page tables;
freeing page tables is just a real case that we can see in the vmalloc/
vfree paths. Theoretically, whenever a kernel page table update is done
and the CPU TLB needs to be flushed, the secondary TLB (i.e., the caches
on the IOMMU) should be flushed accordingly. It's assumed that this
happens in flush_tlb_kernel_range().

Thanks,
baolu

  reply	other threads:[~2025-07-10  2:16 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-07-09  6:28 [PATCH v2 1/1] iommu/sva: Invalidate KVA range on kernel TLB flush Lu Baolu
2025-07-09 15:29 ` Dave Hansen
2025-07-10  2:14   ` Baolu Lu [this message]
2025-07-10  2:55     ` Tian, Kevin
2025-07-10 12:53     ` Dave Hansen
2025-07-10 13:22       ` Jason Gunthorpe
2025-07-10 15:26         ` Dave Hansen
2025-07-11  2:46           ` Tian, Kevin
2025-07-11  2:54           ` Tian, Kevin
2025-07-11  8:17           ` Yu Zhang
2025-07-24  3:01             ` Baolu Lu
2025-07-28 17:36               ` Yu Zhang
2025-07-29  2:08                 ` Baolu Lu
2025-07-24  3:06           ` Baolu Lu
2025-07-11  2:49         ` Tian, Kevin
2025-07-10  3:02 ` Tian, Kevin
2025-07-10  8:11   ` Yu Zhang
2025-07-10  8:15     ` Tian, Kevin
2025-07-10  9:37       ` Yu Zhang
2025-07-10 13:54 ` Peter Zijlstra
2025-07-10 15:53   ` Peter Zijlstra
2025-07-11  3:09     ` Baolu Lu
2025-07-11  8:27       ` Peter Zijlstra
2025-07-16 11:57     ` David Laight
2025-07-17  1:47       ` Baolu Lu
2025-07-11  3:00   ` Baolu Lu
2025-07-11  4:01     ` Tian, Kevin
2025-07-11  8:32     ` Peter Zijlstra
2025-07-11 11:58       ` Jason Gunthorpe
2025-07-15  5:55       ` Baolu Lu
2025-07-15 12:25         ` Jason Gunthorpe
2025-07-16  6:34           ` Baolu Lu
2025-07-16 12:08             ` Jason Gunthorpe
2025-07-17  1:43               ` Baolu Lu
2025-07-17 11:50                 ` Vasant Hegde
2025-07-11 11:54     ` Jason Gunthorpe
2025-07-16 10:54 ` Yi Liu
2025-07-17  1:51   ` Baolu Lu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=228cd2c9-b781-4505-8b54-42dab03f3650@linux.intel.com \
    --to=baolu.lu@linux.intel.com \
    --cc=apopple@nvidia.com \
    --cc=dave.hansen@intel.com \
    --cc=iommu@lists.linux.dev \
    --cc=jannh@google.com \
    --cc=jean-philippe@linaro.org \
    --cc=jgg@nvidia.com \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=luto@kernel.org \
    --cc=peterz@infradead.org \
    --cc=robin.murphy@arm.com \
    --cc=security@kernel.org \
    --cc=stable@vger.kernel.org \
    --cc=urezki@gmail.com \
    --cc=vasant.hegde@amd.com \
    --cc=will@kernel.org \
    --cc=yi1.lai@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox