Re: [PATCH 2/4] KVM: s390: vsie: zero stale crypto bits

Claudio Imbrenda <[email protected]>
Newsgroups org.kernel.vger.linux-s390,org.kernel.vger.kvm
Organization IBM
Message-ID <20260812131856.35aea6b8@p-imbrenda>
On Tue, 11 Aug 2026 17:37:36 +0200
Christian Borntraeger <[email protected]> wrote:

> When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
> the bits 64..255 are unchanged from whatever is in the vsie page in the
> crycb and thus in the apcb. This gives a nested guest potential access
> to a device no longer available. Zero out the remaining bits.
> 
> Fixes: 6b79de4b056e ("KVM: s390: vsie: allow guest FORMAT-1 CRYCB on host FORMAT-2")
> Cc: [email protected]
> Signed-off-by: Christian Borntraeger <[email protected]>

Reviewed-by: Claudio Imbrenda <[email protected]>

> ---
>  arch/s390/kvm/vsie.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/arch/s390/kvm/vsie.c b/arch/s390/kvm/vsie.c
> index f546239d8ff8..7971947d2fe5 100644
> --- a/arch/s390/kvm/vsie.c
> +++ b/arch/s390/kvm/vsie.c
> @@ -172,6 +172,7 @@ static int setup_apcb10(struct kvm_vcpu *vcpu, struct kvm_s390_apcb1 *apcb_s,
>  			    sizeof(struct kvm_s390_apcb0)))
>  		return -EFAULT;
>  
> +	memset(apcb_s, 0, sizeof(*apcb_s));
>  	apcb_s->apm[0] = apcb_h->apm[0] & tmp.apm[0];
>  	apcb_s->aqm[0] = apcb_h->aqm[0] & tmp.aqm[0] & 0xffff000000000000UL;
>  	apcb_s->adm[0] = apcb_h->adm[0] & tmp.adm[0] & 0xffff000000000000UL;
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.