Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1315426

[PATCH 3.13.y-ckt 014/108] KVM: x86: Reload pit counters for all channels when restoring state

From Kamal Mostafa <kamal@canonical.com>
Newsgroups linux.kernel
Subject [PATCH 3.13.y-ckt 014/108] KVM: x86: Reload pit counters for all channels when restoring state
Date 2016-01-23 01:00 +0100
Message-ID <qTTMu-2Oo-9@gated-at.bofh.it> (permalink)
References <qTTt7-2G5-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


3.13.11-ckt33 -stable review patch.  If anyone has any objections, please let me know.

---8<------------------------------------------------------------

From: Andrew Honig <ahonig@google.com>

commit 0185604c2d82c560dab2f2933a18f797e74ab5a8 upstream.

Currently if userspace restores the pit counters with a count of 0
on channels 1 or 2 and the guest attempts to read the count on those
channels, then KVM will perform a mod of 0 and crash.  This will ensure
that 0 values are converted to 65536 as per the spec.

This is CVE-2015-7513.

Signed-off-by: Andy Honig <ahonig@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Cc: Moritz Muehlenhoff <jmm@inutil.org>
[ luis: backported to 3.16: adjusted context ]
Signed-off-by: Luis Henriques <luis.henriques@canonical.com>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 arch/x86/kvm/x86.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 8f83ea4..20ced12 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -3505,10 +3505,12 @@ static int kvm_vm_ioctl_get_pit(struct kvm *kvm, struct kvm_pit_state *ps)
 static int kvm_vm_ioctl_set_pit(struct kvm *kvm, struct kvm_pit_state *ps)
 {
 	int r = 0;
+	int i;
 
 	mutex_lock(&kvm->arch.vpit->pit_state.lock);
 	memcpy(&kvm->arch.vpit->pit_state, ps, sizeof(struct kvm_pit_state));
-	kvm_pit_load_count(kvm, 0, ps->channels[0].count, 0);
+	for (i = 0; i < 3; i++)
+		kvm_pit_load_count(kvm, i, ps->channels[i].count, 0);
 	mutex_unlock(&kvm->arch.vpit->pit_state.lock);
 	return r;
 }
@@ -3529,6 +3531,7 @@ static int kvm_vm_ioctl_get_pit2(struct kvm *kvm, struct kvm_pit_state2 *ps)
 static int kvm_vm_ioctl_set_pit2(struct kvm *kvm, struct kvm_pit_state2 *ps)
 {
 	int r = 0, start = 0;
+	int i;
 	u32 prev_legacy, cur_legacy;
 	mutex_lock(&kvm->arch.vpit->pit_state.lock);
 	prev_legacy = kvm->arch.vpit->pit_state.flags & KVM_PIT_FLAGS_HPET_LEGACY;
@@ -3538,7 +3541,8 @@ static int kvm_vm_ioctl_set_pit2(struct kvm *kvm, struct kvm_pit_state2 *ps)
 	memcpy(&kvm->arch.vpit->pit_state.channels, &ps->channels,
 	       sizeof(kvm->arch.vpit->pit_state.channels));
 	kvm->arch.vpit->pit_state.flags = ps->flags;
-	kvm_pit_load_count(kvm, 0, kvm->arch.vpit->pit_state.channels[0].count, start);
+	for (i = 0; i < 3; i++)
+		kvm_pit_load_count(kvm, i, kvm->arch.vpit->pit_state.channels[i].count, start);
 	mutex_unlock(&kvm->arch.vpit->pit_state.lock);
 	return r;
 }
-- 
1.9.1

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[3.13.y-ckt stable] Linux 3.13.11-ckt33 stable review Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 086/108] x86/mce: Ensure offline CPUs don't participate in rendezvous process Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 053/108] xhci: fix usb2 resume timing and races. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 009/108] sh_eth: fix kernel oops in skb_put() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 093/108] async_tx: use GFP_NOWAIT rather than GFP_IO Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 102/108] pinctrl: bcm2835: Fix initial value for direction_output Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 105/108] qlcnic: fix a timeout loop Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 095/108] ftrace/module: Call clean up function when module init fails early Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 088/108] ALSA: hda/realtek - Fix silent headphone output on MacPro 4,1 (v2) Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 107/108] include/linux/mmdebug.h: should include linux/bug.h Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 090/108] mm/memory_hotplug.c: check for missing sections in test_pages_in_a_zone() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 075/108] xen-netback: use RING_COPY_REQUEST() throughout Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 096/108] vmstat: allocate vmstat_wq before it is used Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 103/108] mISDN: fix a loop count Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 092/108] tracing: Fix setting of start_index in find_next() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 099/108] ipv6/addrlabel: fix ip6addrlbl_get() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 091/108] ftrace/scripts: Fix incorrect use of sprintf in recordmcount Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 077/108] xen-blkback: read from indirect descriptors only once Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:40 +0100
  [PATCH 3.13.y-ckt 057/108] mm, vmstat: allow WQ concurrency to discover memory reclaim doesn't make any progress Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 076/108] xen-blkback: only read request operation from shared ring once Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 050/108] ses: Fix problems with simple enclosures Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 059/108] drivers/base/memory.c: prohibit offlining of memory blocks with missing sections Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 049/108] dm btree: fix bufio buffer leaks in dm_btree_del() error path Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 052/108] ses: fix additional element traversal bug Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 073/108] xen: Add RING_COPY_REQUEST() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 072/108] s390/dis: Fix handling of format specifiers Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 070/108] ARC: dw2 unwind: Ignore CIE version !=1 gracefully instead of bailing Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 045/108] dm space map metadata: fix ref counting bug when bootstrapping a new space map Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 071/108] ALSA: hda - Set SKL+ hda controller power at freeze() and thaw() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 068/108] ftrace/scripts: Have recordmcount copy the object file Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 066/108] spi: fix parent-device reference leak Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 064/108] ALSA: usb-audio: Add a more accurate volume quirk for AudioQuest DragonFly Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 058/108] mm: hugetlb: call huge_pte_alloc() only if ptep is null Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 062/108] tty: Fix GPF in flush_to_ldisc() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 082/108] xen/pciback: For XEN_PCI_OP_disable_msi[|x] only disable if device has MSI(X) enabled. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 081/108] xen/pciback: Do not install an IRQ handler for MSI interrupts. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 054/108] USB: add quirk for devices with broken LPM Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 083/108] xen/pciback: Don't allow MSI-X ops if PCI_COMMAND_MEMORY is not set. Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 051/108] vgaarb: fix signal handling in vga_get() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 046/108] ipmi: move timer init to before irq is setup Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 069/108] ARC: dw2 unwind: Reinstante unwinding out of modules Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 074/108] xen-netback: don't use last request to determine minimum Tx credit Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 063/108] genirq: Prevent chip buslock deadlock Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 060/108] sh64: fix __NR_fgetxattr Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 048/108] rfkill: copy the name into the rfkill struct Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 078/108] xen/pciback: Save xen_pci_op commands before processing it Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 079/108] xen/pciback: Return error on XEN_PCI_OP_enable_msi when device has MSI or MSI-X enabled Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 061/108] n_tty: Fix poll() after buffer-limited eof push read Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 056/108] parisc iommu: fix panic due to trying to allocate too large region Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 055/108] powercap / RAPL: fix BIOS lock check Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 080/108] xen/pciback: Return error on XEN_PCI_OP_enable_msix when device has MSI or MSI-X enabled Kamal Mostafa <kamal@canonical.com> - 2016-01-23 00:50 +0100
  [PATCH 3.13.y-ckt 022/108] USB: cdc_acm: Ignore Infineon Flash Loader utility Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 015/108] tools: Add a "make all" rule Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 020/108] iio: fix some warning messages Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 031/108] irqchip/versatile-fpga: Fix PCI IRQ mapping on Versatile PB Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 014/108] KVM: x86: Reload pit counters for all channels when restoring state Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 026/108] drm/ttm: Fixed a read/write lock imbalance Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 023/108] USB: serial: Another Infineon flash loader USB ID Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 042/108] radeon/cik: Fix GFX IB test on Big-Endian Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 025/108] jbd2: Fix unreclaimed pages after truncate in data=journal mode Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 021/108] USB: cp210x: Remove CP2110 ID from compatibility list Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 038/108] ALSA: rme96: Fix unexpected volume reset after rate changes Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 017/108] net: ipmr: fix static mfc/dev leaks on table destruction Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 036/108] SCSI: Fix NULL pointer dereference in runtime PM Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 007/108] ipv6: sctp: clone options to avoid use after free Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 018/108] fuse: break infinite loop in fuse_fill_write_pages() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 041/108] 9p: ->evict_inode() should kick out ->i_data, not ->i_mapping Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 029/108] sata_sil: disable trim Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 040/108] virtio: fix memory leak of virtio ida cache layers Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 010/108] pptp: verify sockaddr_len in pptp_bind() and pptp_connect() Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 043/108] crypto: skcipher - Copy iv from desc even for 0-len walks Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 019/108] usb: gadget: pxa27x: fix suspend callback Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 030/108] staging: lustre: echo_copy.._lsm() dereferences userland pointers directly Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 037/108] usb: xhci: fix config fail of FS hub behind a HS hub with MTT Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 034/108] usb: Use the USB_SS_MULT() macro to decode burst multiplier for log message Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 027/108] i2c: mv64xxx: The n clockdiv factor is 0 based on sunxi SoCs Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 035/108] dm btree: fix leak of bufio-backed block in btree_split_sibling error path Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 033/108] USB: whci-hcd: add check for dma mapping error Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 016/108] efi: Disable interrupts around EFI calls, not in the epilog/prolog calls Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 008/108] net: add validation for the socket syscall protocol argument Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 028/108] AHCI: Fix softreset failed issue of Port Multiplier Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 044/108] dm thin metadata: fix bug when taking a metadata snapshot Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 011/108] bluetooth: Validate socket address length in sco_sock_bind(). Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 012/108] af_unix: Revert 'lock_interruptible' in stream receive code Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:00 +0100
  [PATCH 3.13.y-ckt 005/108] sctp: use the same clock as if sock source timestamps were on Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
  [PATCH 3.13.y-ckt 003/108] gre6: allow to update all parameters via rtnl Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
  [PATCH 3.13.y-ckt 004/108] atl1c: Improve driver not to do order 4 GFP_ATOMIC allocation Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
  [PATCH 3.13.y-ckt 001/108] ARC: Fix silly typo in MAINTAINERS file Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100
  [PATCH 3.13.y-ckt 006/108] sctp: update the netstamp_needed counter when copying sockets Kamal Mostafa <kamal@canonical.com> - 2016-01-23 01:10 +0100

csiph-web