Re: [PATCH 1/2] LoongArch: KVM: EIOINTC: clamp ipnum to valid range in INT_ENCODE mode
Bibo Mao <[email protected]>
| Newsgroups | dev.linux.lists.loongarch,org.kernel.vger.kvm,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
Hi Tao, Thanks to catch this, there is similar modification which can be located at: https://lore.kernel.org/lkml/[email protected]/ Regards Bibo Mao On 2026/7/14 上午9:24, Tao Cui wrote: > From: Tao Cui <[email protected]> > > The IP-number decode in eiointc_set_sw_coreisr() and eiointc_update_irq() > clamps ipnum only in the default (1-hot) mode. In INT_ENCODE mode the raw > ipmap byte (0..255) is used as the index into sw_coreisr[cpu][ipnum], > whose second dimension is LOONGSON_IP_NUM (8), so any ipmap byte >= 8 > accesses the array out of bounds. > > The value is guest-programmable through the EIOINTC virtual extension > (VIRT_CONFIG enables INT_ENCODE and the IPMAP IOCSR write is unvalidated) > and is also restored unvalidated from a migration stream via the > LOAD_FINISHED control attribute, resulting in a host slab out-of-bounds > access reachable from an unprivileged guest. > > Clamp ipnum to [0, LOONGSON_IP_NUM) in INT_ENCODE mode as well. > > Fixes: 3956a52bc05b ("LoongArch: KVM: Add EIOINTC read and write functions") > Cc: [email protected] > Signed-off-by: Tao Cui <[email protected]> > --- > arch/loongarch/kvm/intc/eiointc.c | 4 ++++ > 1 file changed, 4 insertions(+) > > diff --git a/arch/loongarch/kvm/intc/eiointc.c b/arch/loongarch/kvm/intc/eiointc.c > index 2b14485d14a7..0c34d7ab264d 100644 > --- a/arch/loongarch/kvm/intc/eiointc.c > +++ b/arch/loongarch/kvm/intc/eiointc.c > @@ -17,6 +17,8 @@ static void eiointc_set_sw_coreisr(struct loongarch_eiointc *s) > if (!(s->status & BIT(EIOINTC_ENABLE_INT_ENCODE))) { > ipnum = count_trailing_zeros(ipnum); > ipnum = ipnum < 4 ? ipnum : 0; > + } else { > + ipnum = (ipnum < LOONGSON_IP_NUM) ? ipnum : 0; > } > > cpuid = ((u8 *)s->coremap)[irq]; > @@ -42,6 +44,8 @@ static void eiointc_update_irq(struct loongarch_eiointc *s, int irq, int level) > if (!(s->status & BIT(EIOINTC_ENABLE_INT_ENCODE))) { > ipnum = count_trailing_zeros(ipnum); > ipnum = ipnum < 4 ? ipnum : 0; > + } else { > + ipnum = (ipnum < LOONGSON_IP_NUM) ? ipnum : 0; > } > > cpu = s->sw_coremap[irq]; >