Merge tag 'kvm-x86-fixes-6.10-11' of https://github.com/kvm-x86/linux into HEAD
KVM Xen: Fix a bug where KVM fails to check the validity of an incoming userspace virtual address and tries to activate a gfn_to_pfn_cache with a kernel address.
This commit is contained in:
+1
-1
@@ -741,7 +741,7 @@ int kvm_xen_hvm_set_attr(struct kvm *kvm, struct kvm_xen_hvm_attr *data)
|
||||
} else {
|
||||
void __user * hva = u64_to_user_ptr(data->u.shared_info.hva);
|
||||
|
||||
if (!PAGE_ALIGNED(hva) || !access_ok(hva, PAGE_SIZE)) {
|
||||
if (!PAGE_ALIGNED(hva)) {
|
||||
r = -EINVAL;
|
||||
} else if (!hva) {
|
||||
kvm_gpc_deactivate(&kvm->arch.xen.shinfo_cache);
|
||||
|
||||
@@ -430,6 +430,9 @@ int kvm_gpc_activate(struct gfn_to_pfn_cache *gpc, gpa_t gpa, unsigned long len)
|
||||
|
||||
int kvm_gpc_activate_hva(struct gfn_to_pfn_cache *gpc, unsigned long uhva, unsigned long len)
|
||||
{
|
||||
if (!access_ok((void __user *)uhva, len))
|
||||
return -EINVAL;
|
||||
|
||||
return __kvm_gpc_activate(gpc, INVALID_GPA, uhva, len);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user