summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSean Christopherson <seanjc@google.com>2023-01-07 01:10:21 +0000
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2023-04-05 11:25:01 +0200
commit61e0863dc8dd7c73568397ad920e8ac14b78e466 (patch)
tree34fd7894ce832229bedd86cb167be0f426de9f6e
parent4483dc41d123e17fbfc466be57afa659bdd382f8 (diff)
downloadlinux-stable-61e0863dc8dd7c73568397ad920e8ac14b78e466.tar.gz
linux-stable-61e0863dc8dd7c73568397ad920e8ac14b78e466.tar.bz2
linux-stable-61e0863dc8dd7c73568397ad920e8ac14b78e466.zip
KVM: x86: Inject #GP on x2APIC WRMSR that sets reserved bits 63:32
commit ab52be1b310bcb39e6745d34a8f0e8475d67381a upstream. Reject attempts to set bits 63:32 for 32-bit x2APIC registers, i.e. all x2APIC registers except ICR. Per Intel's SDM: Non-zero writes (by WRMSR instruction) to reserved bits to these registers will raise a general protection fault exception Opportunistically fix a typo in a nearby comment. Reported-by: Marc Orr <marcorr@google.com> Cc: stable@vger.kernel.org Reviewed-by: Maxim Levitsky <mlevitsk@redhat.com> Link: https://lore.kernel.org/r/20230107011025.565472-3-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com> Signed-off-by: Alejandro Jimenez <alejandro.j.jimenez@oracle.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
-rw-r--r--arch/x86/kvm/lapic.c8
1 files changed, 8 insertions, 0 deletions
diff --git a/arch/x86/kvm/lapic.c b/arch/x86/kvm/lapic.c
index 8c9e41ff2a24..243aa43f7113 100644
--- a/arch/x86/kvm/lapic.c
+++ b/arch/x86/kvm/lapic.c
@@ -2802,6 +2802,10 @@ int kvm_x2apic_msr_write(struct kvm_vcpu *vcpu, u32 msr, u64 data)
/* if this is ICR write vector before command */
if (reg == APIC_ICR)
kvm_lapic_reg_write(apic, APIC_ICR2, (u32)(data >> 32));
+ else if (data >> 32)
+ /* Bits 63:32 are reserved in all other registers. */
+ return 1;
+
return kvm_lapic_reg_write(apic, reg, (u32)data);
}
@@ -2836,6 +2840,10 @@ int kvm_hv_vapic_msr_write(struct kvm_vcpu *vcpu, u32 reg, u64 data)
/* if this is ICR write vector before command */
if (reg == APIC_ICR)
kvm_lapic_reg_write(apic, APIC_ICR2, (u32)(data >> 32));
+ else if (data >> 32)
+ /* Bits 63:32 are reserved in all other registers. */
+ return 1;
+
return kvm_lapic_reg_write(apic, reg, (u32)data);
}