Commit b5b68519 authored by Marc Zyngier's avatar Marc Zyngier Committed by Zhang Zekun
Browse files

KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3

stable inclusion
from stable-v5.10.225
commit 15818af2f7aa55eff375333cb7689df15d3f24ef
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAR5D2
CVE: CVE-2024-46707

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=15818af2f7aa55eff375333cb7689df15d3f24ef



--------------------------------------------------

commit 3e6245ebe7ef341639e9a7e402b3ade8ad45a19f upstream.

On a system with a GICv3, if a guest hasn't been configured with
GICv3 and that the host is not capable of GICv2 emulation,
a write to any of the ICC_*SGI*_EL1 registers is trapped to EL2.

We therefore try to emulate the SGI access, only to hit a NULL
pointer as no private interrupt is allocated (no GIC, remember?).

The obvious fix is to give the guest what it deserves, in the
shape of a UNDEF exception.

Reported-by: default avatarAlexander Potapenko <glider@google.com>
Signed-off-by: default avatarMarc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20240820100349.3544850-2-maz@kernel.org


Signed-off-by: default avatarOliver Upton <oliver.upton@linux.dev>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Conflicts:
	arch/arm64/kvm/vgic/vgic.h
[Code context change only]
Signed-off-by: default avatarZhang Zekun <zhangzekun11@huawei.com>
parent dc55753c
Loading
Loading
Loading
Loading
+6 −0
Original line number Diff line number Diff line
@@ -30,6 +30,7 @@
#include <trace/events/kvm.h>

#include "sys_regs.h"
#include "vgic/vgic.h"

#include "trace.h"

@@ -275,6 +276,11 @@ static bool access_gic_sgi(struct kvm_vcpu *vcpu,
{
	bool g1;

	if (!kvm_has_gicv3(vcpu->kvm)) {
		kvm_inject_undefined(vcpu);
		return false;
	}

	if (!p->is_write)
		return read_from_write_only(vcpu, p, r);

+7 −0
Original line number Diff line number Diff line
@@ -330,4 +330,11 @@ void vgic_v4_configure_vsgis(struct kvm *kvm);
void vgic_v4_get_vlpi_state(struct vgic_irq *irq, bool *val);
void vgic_v4_configure_vtimer(struct kvm *kvm);

static inline bool kvm_has_gicv3(struct kvm *kvm)
{
	return (static_branch_unlikely(&kvm_vgic_global_state.gicv3_cpuif) &&
		irqchip_in_kernel(kvm) &&
		kvm->arch.vgic.vgic_model == KVM_DEV_TYPE_ARM_VGIC_V3);
}

#endif