diff options
| author | Sean Christopherson <seanjc@google.com> | 2026-08-06 10:06:02 -0700 |
|---|---|---|
| committer | Sean Christopherson <seanjc@google.com> | 2026-09-22 06:40:39 -0700 |
| commit | ea93efec4dda2ca8c33dc88cf4d389a980a358df (patch) | |
| tree | 272c60dee458ca18c32cd0bac95a89f344768533 /arch/x86 | |
| parent | aec196ba2affa5b396ed1bc16340067d66972f24 (diff) | |
| download | linux-next-ea93efec4dda2ca8c33dc88cf4d389a980a358df.tar.gz linux-next-ea93efec4dda2ca8c33dc88cf4d389a980a358df.zip | |
KVM: TDX: Fix a benign off-by-one bug on the end GPA for INIT_MEM_REGION
When verifying that the incoming GPA rage for INIT_MEM_REGION doesn't wrap,
check the inclusive last GPA, not the exclusive last GPA. Super duper
technically, it's ok if the very last GPA is -1ull. In practice, the flaw
is benign as KVM x86 disallows memslots with GPAs that exceed MAXPHYADDR,
i.e. INIT_MEM_REGION would fail with -EINVAL anyways due to the memslot
check in kvm_gmem_populate().
Opportunistically use check_add_overflow() instead of manually checking for
wrap, mostly so that the inclusive math doesn't need to be copy+pasted in
the "is private" check.
Fixes: c846b451d3c5 ("KVM: TDX: Add an ioctl to create initial guest memory")
Reviewed-by: Yan Zhao <yan.y.zhao@intel.com>
Tested-by: Yan Zhao <yan.y.zhao@intel.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Link: https://patch.msgid.link/20260806170602.4112602-3-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Diffstat (limited to 'arch/x86')
| -rw-r--r-- | arch/x86/kvm/vmx/tdx.c | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index d991996259a8..2a3acf493cb5 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -3257,7 +3257,7 @@ static int tdx_vcpu_init_mem_region(struct kvm_vcpu *vcpu, struct kvm_tdx_cmd *c struct kvm_tdx *kvm_tdx = to_kvm_tdx(kvm); struct kvm_tdx_init_mem_region region; struct tdx_gmem_post_populate_arg arg; - gpa_t nr_bytes; + gpa_t nr_bytes, end_gpa; long gmem_ret; int ret; @@ -3279,9 +3279,9 @@ static int tdx_vcpu_init_mem_region(struct kvm_vcpu *vcpu, struct kvm_tdx_cmd *c return -EINVAL; if (check_shl_overflow(region.nr_pages, PAGE_SHIFT, &nr_bytes) || - region.gpa + nr_bytes <= region.gpa || + check_add_overflow(region.gpa, nr_bytes - 1, &end_gpa) || !vt_is_tdx_private_gpa(kvm, region.gpa) || - !vt_is_tdx_private_gpa(kvm, region.gpa + nr_bytes - 1)) + !vt_is_tdx_private_gpa(kvm, end_gpa)) return -EINVAL; ret = 0; |
