|
Juergen Gross |
754476 |
Patch-mainline: v5.6-rc1
|
|
Juergen Gross |
754476 |
Git-commit: 6ec4c5eee1750d5d17951c4e1960d953376a0dda
|
|
Juergen Gross |
754476 |
From: Marios Pomonis <pomonis@google.com>
|
|
Juergen Gross |
754476 |
Date: Wed, 11 Dec 2019 12:47:49 -0800
|
|
Juergen Gross |
754476 |
Subject: [PATCH] KVM: x86: Protect MSR-based index computations from
|
|
Juergen Gross |
754476 |
Spectre-v1/L1TF attacks in x86.c
|
|
Juergen Gross |
754476 |
References: bsc#1164733
|
|
Juergen Gross |
754476 |
|
|
Juergen Gross |
754476 |
This fixes a Spectre-v1/L1TF vulnerability in set_msr_mce() and
|
|
Juergen Gross |
754476 |
get_msr_mce().
|
|
Juergen Gross |
754476 |
Both functions contain index computations based on the
|
|
Juergen Gross |
754476 |
(attacker-controlled) MSR number.
|
|
Juergen Gross |
754476 |
|
|
Juergen Gross |
754476 |
Fixes: 890ca9aefa78 ("KVM: Add MCE support")
|
|
Juergen Gross |
754476 |
|
|
Juergen Gross |
754476 |
Signed-off-by: Nick Finco <nifi@google.com>
|
|
Juergen Gross |
754476 |
Signed-off-by: Marios Pomonis <pomonis@google.com>
|
|
Juergen Gross |
754476 |
Reviewed-by: Andrew Honig <ahonig@google.com>
|
|
Juergen Gross |
754476 |
Cc: stable@vger.kernel.org
|
|
Juergen Gross |
754476 |
Reviewed-by: Jim Mattson <jmattson@google.com>
|
|
Juergen Gross |
754476 |
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
|
Juergen Gross |
754476 |
Signed-off-by: Juergen Gross <jgross@suse.com>
|
|
Juergen Gross |
754476 |
---
|
|
Juergen Gross |
754476 |
arch/x86/kvm/x86.c | 10 ++++++++--
|
|
Juergen Gross |
754476 |
1 file changed, 8 insertions(+), 2 deletions(-)
|
|
Juergen Gross |
754476 |
|
|
Juergen Gross |
754476 |
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
|
|
Juergen Gross |
754476 |
index 985066e1bda5..913e55f6dca3 100644
|
|
Juergen Gross |
754476 |
--- a/arch/x86/kvm/x86.c
|
|
Juergen Gross |
754476 |
+++ b/arch/x86/kvm/x86.c
|
|
Juergen Gross |
754476 |
@@ -2138,7 +2138,10 @@ static int set_msr_mce(struct kvm_vcpu *vcpu, struct msr_data *msr_info)
|
|
Juergen Gross |
754476 |
default:
|
|
Juergen Gross |
754476 |
if (msr >= MSR_IA32_MC0_CTL &&
|
|
Juergen Gross |
754476 |
msr < MSR_IA32_MCx_CTL(bank_num)) {
|
|
Juergen Gross |
754476 |
- u32 offset = msr - MSR_IA32_MC0_CTL;
|
|
Juergen Gross |
754476 |
+ u32 offset = array_index_nospec(
|
|
Juergen Gross |
754476 |
+ msr - MSR_IA32_MC0_CTL,
|
|
Juergen Gross |
754476 |
+ MSR_IA32_MCx_CTL(bank_num) - MSR_IA32_MC0_CTL);
|
|
Juergen Gross |
754476 |
+
|
|
Juergen Gross |
754476 |
/* only 0 or all 1s can be written to IA32_MCi_CTL
|
|
Juergen Gross |
754476 |
* some Linux kernels though clear bit 10 in bank 4 to
|
|
Juergen Gross |
754476 |
* workaround a BIOS/GART TBL issue on AMD K8s, ignore
|
|
Juergen Gross |
754476 |
@@ -2526,7 +2529,10 @@ static int get_msr_mce(struct kvm_vcpu *vcpu, u32 msr, u64 *pdata, bool host)
|
|
Juergen Gross |
754476 |
default:
|
|
Juergen Gross |
754476 |
if (msr >= MSR_IA32_MC0_CTL &&
|
|
Juergen Gross |
754476 |
msr < MSR_IA32_MCx_CTL(bank_num)) {
|
|
Juergen Gross |
754476 |
- u32 offset = msr - MSR_IA32_MC0_CTL;
|
|
Juergen Gross |
754476 |
+ u32 offset = array_index_nospec(
|
|
Juergen Gross |
754476 |
+ msr - MSR_IA32_MC0_CTL,
|
|
Juergen Gross |
754476 |
+ MSR_IA32_MCx_CTL(bank_num) - MSR_IA32_MC0_CTL);
|
|
Juergen Gross |
754476 |
+
|
|
Juergen Gross |
754476 |
data = vcpu->arch.mce_banks[offset];
|
|
Juergen Gross |
754476 |
break;
|
|
Juergen Gross |
754476 |
}
|
|
Juergen Gross |
754476 |
--
|
|
Juergen Gross |
754476 |
2.16.4
|
|
Juergen Gross |
754476 |
|