Re: [PATCH] KVM: riscv: Fix Spectre-v1 in vector register access
Anup Patel <[email protected]> Wed, 15 Jul 2026 18:20:55 +0530
| Newsgroups | org.infradead.lists.kvm-riscv,org.infradead.lists.linux-riscv,org.kernel.vger.kvm,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAAhSdy1cSDB-8XbkjMzhZafvOwM=ghjcaoiGd3NXGxLnAUMzkw@mail.gmail.com> |
On Wed, Jul 15, 2026 at 8:38 AM Zongmin Zhou <[email protected]> wrote: > > From: Zongmin Zhou <[email protected]> > > User-controlled register indices from the ONE_REG ioctl are used to > index into the vector register buffer (v0..v31). Sanitize the calculated > offset with array_index_nospec() to prevent speculative out-of-bounds > access. > > Signed-off-by: Zongmin Zhou <[email protected]> LGTM. Reviewed-by: Anup Patel <[email protected]> Queued this patch as a fix for Linux-7.2-rcX Thanks, Anup > --- > arch/riscv/kvm/vcpu_vector.c | 14 ++++++++++++-- > 1 file changed, 12 insertions(+), 2 deletions(-) > > diff --git a/arch/riscv/kvm/vcpu_vector.c b/arch/riscv/kvm/vcpu_vector.c > index 62d2fb77bb9b..3708616e2c32 100644 > --- a/arch/riscv/kvm/vcpu_vector.c > +++ b/arch/riscv/kvm/vcpu_vector.c > @@ -10,6 +10,7 @@ > #include <linux/errno.h> > #include <linux/err.h> > #include <linux/kvm_host.h> > +#include <linux/nospec.h> > #include <linux/uaccess.h> > #include <asm/cpufeature.h> > #include <asm/kvm_isa.h> > @@ -129,11 +130,20 @@ static int kvm_riscv_vcpu_vreg_addr(struct kvm_vcpu *vcpu, > return -ENOENT; > } > } else if (reg_num <= KVM_REG_RISCV_VECTOR_REG(31)) { > + unsigned long reg_offset; > + > if (reg_size != vlenb) > return -EINVAL; > WARN_ON(!cntx->vector.datap); > - *reg_addr = cntx->vector.datap + > - (reg_num - KVM_REG_RISCV_VECTOR_REG(0)) * vlenb; > + /* > + * The reg_num is derived from the userspace-provided ONE_REG > + * id. Sanitize it with array_index_nospec() to prevent > + * speculative out-of-bounds access to the vector register > + * buffer (32 vector registers: v0..v31). > + */ > + reg_offset = array_index_nospec( > + reg_num - KVM_REG_RISCV_VECTOR_REG(0), 32); > + *reg_addr = cntx->vector.datap + reg_offset * vlenb; > } else { > return -ENOENT; > } > -- > 2.34.1 > > > No virus found > Checked by Hillstone Network AntiVirus > -- kvm-riscv mailing list [email protected] http://lists.infradead.org/mailman/listinfo/kvm-riscv