Linux s390 Architecture development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mike Rapoport (Microsoft)" <rppt@kernel.org>
Cc: "Heiko Carstens" <hca@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	"Vasily Gorbik" <gor@linux.ibm.com>,
	linux-s390@vger.kernel.org,
	"Christian Borntraeger" <borntraeger@linux.ibm.com>,
	kvm@vger.kernel.org
Subject: Re: [PATCH 2/4] KVM: s390: Replace get_zeroed_page() with kzalloc() for the STSI buffer
Date: Wed, 02 Sep 2026 06:22:22 +0000	[thread overview]
Message-ID: <20260902062223.5295D1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260902-s390-kvm-v1-2-3bc0986550b1@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] Replacing get_zeroed_page() with kzalloc() breaks the hardware 4K alignment requirement for the STSI buffer, creating a Guest-to-Host Denial of Service (DoS) vulnerability.
--

commit bcd4e89cdbdb3a1d43d3845b698f4de5d334121d
Author: Mike Rapoport (Microsoft) <rppt@kernel.org>

KVM: s390: Replace get_zeroed_page() with kzalloc() for the STSI buffer

This commit replaces get_zeroed_page() with kzalloc() for allocating
the STSI response block buffer in the s390 KVM subsystem.

Link: https://lore.kernel.org/all/635405e4-9423-4a25-a6e7-e03c8ea0bcbe@redhat.com

> diff --git a/arch/s390/kvm/s390/priv.c b/arch/s390/kvm/s390/priv.c
> index b3cb2c2c3aa71..856939acf012f 100644
> --- a/arch/s390/kvm/s390/priv.c
> +++ b/arch/s390/kvm/s390/priv.c
[ ... ]
> @@ -911,19 +912,19 @@ static int handle_stsi(struct kvm_vcpu *vcpu)
>  	switch (fc) {
>  	case 1: /* same handling for 1 and 2 */
>  	case 2:
> -		mem = get_zeroed_page(GFP_KERNEL_ACCOUNT);
> +		mem = kzalloc(PAGE_SIZE, GFP_KERNEL_ACCOUNT);
>  		if (!mem)
>  			goto out_no_data;
> -		if (stsi((void *) mem, fc, sel1, sel2))
> +		if (stsi(mem, fc, sel1, sel2))

[Severity: Critical]
Does this allocation guarantee the 4K alignment required by the STSI hardware
instruction?

While kzalloc() for PAGE_SIZE might often return page-aligned memory, it is
not strictly guaranteed, especially if slab debugging (CONFIG_SLUB_DEBUG)
with redzoning or CONFIG_KASAN is enabled.

If the allocated memory is not 4K-aligned, the inline stsi() assembly will
trigger a specification exception (Program Check 6). Because there is no
exception table entry for this inline assembly, this will crash the host
kernel.

Since an unprivileged KVM guest can readily execute the STSI instruction
and trap to the host, could this allow a guest-to-host denial of service?

>  			goto out_no_data;
>  		break;
>  	case 3:
>  		if (sel1 != 2 || sel2 != 2)
>  			goto out_no_data;
> -		mem = get_zeroed_page(GFP_KERNEL_ACCOUNT);
> +		mem = kzalloc(PAGE_SIZE, GFP_KERNEL_ACCOUNT);
>  		if (!mem)
>  			goto out_no_data;
> -		handle_stsi_3_2_2(vcpu, (void *) mem);
> +		handle_stsi_3_2_2(vcpu, mem);

[Severity: Critical]
Similarly, passing this potentially misaligned memory into handle_stsi_3_2_2()
can trigger the same specification exception when it executes the STSI
instruction internally.

Should these allocations continue to use get_zeroed_page() to ensure the
strict page alignment required by the hardware?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260902-s390-kvm-v1-0-3bc0986550b1@kernel.org?part=2

  reply	other threads:[~2026-09-02  6:22 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02  6:15 [PATCH 0/4] KVM: s390: replace page allocator calls with kzalloc() Mike Rapoport (Microsoft)
2026-09-02  6:15 ` [PATCH 1/4] KVM: s390: Replace get_zeroed_page() with kzalloc() for the STHYI buffer Mike Rapoport (Microsoft)
2026-09-02  6:19   ` sashiko-bot
2026-09-02  6:15 ` [PATCH 2/4] KVM: s390: Replace get_zeroed_page() with kzalloc() for the STSI buffer Mike Rapoport (Microsoft)
2026-09-02  6:22   ` sashiko-bot [this message]
2026-09-02  7:55     ` Mike Rapoport
2026-09-02  6:15 ` [PATCH 3/4] KVM: s390: Replace get_zeroed_page() with kzalloc() for the GIB Mike Rapoport (Microsoft)
2026-09-02  6:28   ` sashiko-bot
2026-09-02  6:15 ` [PATCH 4/4] KVM: s390: Replace get_zeroed_page() with kzalloc() for sie_page2 and CMMA Mike Rapoport (Microsoft)
2026-09-02  6:26   ` sashiko-bot
2026-09-02 11:06 ` [PATCH 0/4] KVM: s390: replace page allocator calls with kzalloc() Claudio Imbrenda

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260902062223.5295D1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=rppt@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox