summaryrefslogtreecommitdiff
path: root/arch/x86
diff options
context:
space:
mode:
authorSean Christopherson <seanjc@google.com>2026-08-06 10:06:02 -0700
committerSean Christopherson <seanjc@google.com>2026-09-22 06:40:39 -0700
commitea93efec4dda2ca8c33dc88cf4d389a980a358df (patch)
tree272c60dee458ca18c32cd0bac95a89f344768533 /arch/x86
parentaec196ba2affa5b396ed1bc16340067d66972f24 (diff)
downloadlinux-next-ea93efec4dda2ca8c33dc88cf4d389a980a358df.tar.gz
linux-next-ea93efec4dda2ca8c33dc88cf4d389a980a358df.zip
KVM: TDX: Fix a benign off-by-one bug on the end GPA for INIT_MEM_REGION
When verifying that the incoming GPA rage for INIT_MEM_REGION doesn't wrap, check the inclusive last GPA, not the exclusive last GPA. Super duper technically, it's ok if the very last GPA is -1ull. In practice, the flaw is benign as KVM x86 disallows memslots with GPAs that exceed MAXPHYADDR, i.e. INIT_MEM_REGION would fail with -EINVAL anyways due to the memslot check in kvm_gmem_populate(). Opportunistically use check_add_overflow() instead of manually checking for wrap, mostly so that the inclusive math doesn't need to be copy+pasted in the "is private" check. Fixes: c846b451d3c5 ("KVM: TDX: Add an ioctl to create initial guest memory") Reviewed-by: Yan Zhao <yan.y.zhao@intel.com> Tested-by: Yan Zhao <yan.y.zhao@intel.com> Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com> Link: https://patch.msgid.link/20260806170602.4112602-3-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
Diffstat (limited to 'arch/x86')
-rw-r--r--arch/x86/kvm/vmx/tdx.c6
1 files changed, 3 insertions, 3 deletions
diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c
index d991996259a8..2a3acf493cb5 100644
--- a/arch/x86/kvm/vmx/tdx.c
+++ b/arch/x86/kvm/vmx/tdx.c
@@ -3257,7 +3257,7 @@ static int tdx_vcpu_init_mem_region(struct kvm_vcpu *vcpu, struct kvm_tdx_cmd *c
struct kvm_tdx *kvm_tdx = to_kvm_tdx(kvm);
struct kvm_tdx_init_mem_region region;
struct tdx_gmem_post_populate_arg arg;
- gpa_t nr_bytes;
+ gpa_t nr_bytes, end_gpa;
long gmem_ret;
int ret;
@@ -3279,9 +3279,9 @@ static int tdx_vcpu_init_mem_region(struct kvm_vcpu *vcpu, struct kvm_tdx_cmd *c
return -EINVAL;
if (check_shl_overflow(region.nr_pages, PAGE_SHIFT, &nr_bytes) ||
- region.gpa + nr_bytes <= region.gpa ||
+ check_add_overflow(region.gpa, nr_bytes - 1, &end_gpa) ||
!vt_is_tdx_private_gpa(kvm, region.gpa) ||
- !vt_is_tdx_private_gpa(kvm, region.gpa + nr_bytes - 1))
+ !vt_is_tdx_private_gpa(kvm, end_gpa))
return -EINVAL;
ret = 0;