Re: [PATCH 1/2] LoongArch: KVM: EIOINTC: clamp ipnum to valid range in INT_ENCODE mode
Tao Cui <[email protected]>
| Newsgroups | dev.linux.lists.loongarch,org.kernel.vger.kvm,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
在 2026/7/14 10:32, Bibo Mao 写道: > Hi Tao, > > Thanks to catch this, there is similar modification which can be located at: > https://lore.kernel.org/lkml/[email protected]/ > Hi Bibo, Haha, looks like we raced to the same fix :) I came across it while debugging VM migration (the LOAD_FINISHED restore path). Your patch takes priority — I'll go ahead and drop my series. Thanks, Tao > Regards > Bibo Mao > > On 2026/7/14 上午9:24, Tao Cui wrote: >> From: Tao Cui <[email protected]> >> >> The IP-number decode in eiointc_set_sw_coreisr() and eiointc_update_irq() >> clamps ipnum only in the default (1-hot) mode. In INT_ENCODE mode the raw >> ipmap byte (0..255) is used as the index into sw_coreisr[cpu][ipnum], >> whose second dimension is LOONGSON_IP_NUM (8), so any ipmap byte >= 8 >> accesses the array out of bounds. >> >> The value is guest-programmable through the EIOINTC virtual extension >> (VIRT_CONFIG enables INT_ENCODE and the IPMAP IOCSR write is unvalidated) >> and is also restored unvalidated from a migration stream via the >> LOAD_FINISHED control attribute, resulting in a host slab out-of-bounds >> access reachable from an unprivileged guest. >> >> Clamp ipnum to [0, LOONGSON_IP_NUM) in INT_ENCODE mode as well. >> >> Fixes: 3956a52bc05b ("LoongArch: KVM: Add EIOINTC read and write functions") >> Cc: [email protected] >> Signed-off-by: Tao Cui <[email protected]> >> --- >> arch/loongarch/kvm/intc/eiointc.c | 4 ++++ >> 1 file changed, 4 insertions(+) >> >> diff --git a/arch/loongarch/kvm/intc/eiointc.c b/arch/loongarch/kvm/intc/eiointc.c >> index 2b14485d14a7..0c34d7ab264d 100644 >> --- a/arch/loongarch/kvm/intc/eiointc.c >> +++ b/arch/loongarch/kvm/intc/eiointc.c >> @@ -17,6 +17,8 @@ static void eiointc_set_sw_coreisr(struct loongarch_eiointc *s) >> if (!(s->status & BIT(EIOINTC_ENABLE_INT_ENCODE))) { >> ipnum = count_trailing_zeros(ipnum); >> ipnum = ipnum < 4 ? ipnum : 0; >> + } else { >> + ipnum = (ipnum < LOONGSON_IP_NUM) ? ipnum : 0; >> } >> cpuid = ((u8 *)s->coremap)[irq]; >> @@ -42,6 +44,8 @@ static void eiointc_update_irq(struct loongarch_eiointc *s, int irq, int level) >> if (!(s->status & BIT(EIOINTC_ENABLE_INT_ENCODE))) { >> ipnum = count_trailing_zeros(ipnum); >> ipnum = ipnum < 4 ? ipnum : 0; >> + } else { >> + ipnum = (ipnum < LOONGSON_IP_NUM) ? ipnum : 0; >> } >> cpu = s->sw_coremap[irq]; >> >