Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1275350
| From | Jiri Slaby <jslaby@suse.cz> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 3.12 66/72] KVM: x86: work around infinite loop in microcode when #AC is delivered |
| Date | 2015-11-23 14:20 +0100 |
| Message-ID | <qxZcg-2dc-71@gated-at.bofh.it> (permalink) |
| References | <qxZcd-2dc-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
From: Eric Northup <digitaleric@google.com>
3.12-stable review patch. If anyone has any objections, please let me know.
===============
commit 54a20552e1eae07aa240fa370a0293e006b5faed upstream.
It was found that a guest can DoS a host by triggering an infinite
stream of "alignment check" (#AC) exceptions. This causes the
microcode to enter an infinite loop where the core never receives
another interrupt. The host kernel panics pretty quickly due to the
effects (CVE-2015-5307).
Signed-off-by: Eric Northup <digitaleric@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
arch/x86/include/uapi/asm/svm.h | 1 +
arch/x86/kvm/svm.c | 8 ++++++++
arch/x86/kvm/vmx.c | 5 ++++-
3 files changed, 13 insertions(+), 1 deletion(-)
diff --git a/arch/x86/include/uapi/asm/svm.h b/arch/x86/include/uapi/asm/svm.h
index b5d7640abc5d..8a4add8e4639 100644
--- a/arch/x86/include/uapi/asm/svm.h
+++ b/arch/x86/include/uapi/asm/svm.h
@@ -100,6 +100,7 @@
{ SVM_EXIT_EXCP_BASE + UD_VECTOR, "UD excp" }, \
{ SVM_EXIT_EXCP_BASE + PF_VECTOR, "PF excp" }, \
{ SVM_EXIT_EXCP_BASE + NM_VECTOR, "NM excp" }, \
+ { SVM_EXIT_EXCP_BASE + AC_VECTOR, "AC excp" }, \
{ SVM_EXIT_EXCP_BASE + MC_VECTOR, "MC excp" }, \
{ SVM_EXIT_INTR, "interrupt" }, \
{ SVM_EXIT_NMI, "nmi" }, \
diff --git a/arch/x86/kvm/svm.c b/arch/x86/kvm/svm.c
index d1a065ec683f..db4108b82e6b 100644
--- a/arch/x86/kvm/svm.c
+++ b/arch/x86/kvm/svm.c
@@ -1103,6 +1103,7 @@ static void init_vmcb(struct vcpu_svm *svm)
set_exception_intercept(svm, PF_VECTOR);
set_exception_intercept(svm, UD_VECTOR);
set_exception_intercept(svm, MC_VECTOR);
+ set_exception_intercept(svm, AC_VECTOR);
set_intercept(svm, INTERCEPT_INTR);
set_intercept(svm, INTERCEPT_NMI);
@@ -1765,6 +1766,12 @@ static int ud_interception(struct vcpu_svm *svm)
return 1;
}
+static int ac_interception(struct vcpu_svm *svm)
+{
+ kvm_queue_exception_e(&svm->vcpu, AC_VECTOR, 0);
+ return 1;
+}
+
static void svm_fpu_activate(struct kvm_vcpu *vcpu)
{
struct vcpu_svm *svm = to_svm(vcpu);
@@ -3285,6 +3292,7 @@ static int (*const svm_exit_handlers[])(struct vcpu_svm *svm) = {
[SVM_EXIT_EXCP_BASE + PF_VECTOR] = pf_interception,
[SVM_EXIT_EXCP_BASE + NM_VECTOR] = nm_interception,
[SVM_EXIT_EXCP_BASE + MC_VECTOR] = mc_interception,
+ [SVM_EXIT_EXCP_BASE + AC_VECTOR] = ac_interception,
[SVM_EXIT_INTR] = intr_interception,
[SVM_EXIT_NMI] = nmi_interception,
[SVM_EXIT_SMI] = nop_on_interception,
diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c
index f5ddacc4c885..53fede68963d 100644
--- a/arch/x86/kvm/vmx.c
+++ b/arch/x86/kvm/vmx.c
@@ -1388,7 +1388,7 @@ static void update_exception_bitmap(struct kvm_vcpu *vcpu)
u32 eb;
eb = (1u << PF_VECTOR) | (1u << UD_VECTOR) | (1u << MC_VECTOR) |
- (1u << NM_VECTOR) | (1u << DB_VECTOR);
+ (1u << NM_VECTOR) | (1u << DB_VECTOR) | (1u << AC_VECTOR);
if ((vcpu->guest_debug &
(KVM_GUESTDBG_ENABLE | KVM_GUESTDBG_USE_SW_BP)) ==
(KVM_GUESTDBG_ENABLE | KVM_GUESTDBG_USE_SW_BP))
@@ -4812,6 +4812,9 @@ static int handle_exception(struct kvm_vcpu *vcpu)
return handle_rmode_exception(vcpu, ex_no, error_code);
switch (ex_no) {
+ case AC_VECTOR:
+ kvm_queue_exception_e(vcpu, AC_VECTOR, error_code);
+ return 1;
case DB_VECTOR:
dr6 = vmcs_readl(EXIT_QUALIFICATION);
if (!(vcpu->guest_debug &
--
2.6.3
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 3.12 00/72] 3.12.51-stable review Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:10 +0100
[PATCH 3.12 48/72] netfilter: xt_NFQUEUE: fix --queue-bypass regression Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 64/72] KEYS: Fix crash when attempt to garbage collect an uninstantiated keyring Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 63/72] KEYS: Fix race between key destruction and finding a keyring by name Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 55/72] net: sun4i-emac: fix memory leak on bad packet Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 54/72] ceph: fix kick_requests() Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 50/72] bridge: superfluous skb->nfct check in br_nf_dev_queue_xmit Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 56/72] macmace: add missing platform_set_drvdata() in mace_probe() Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 52/72] ceph: make sure request isn't in any waiting list when kicking request. Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 58/72] r8169: disable L23 Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 66/72] KVM: x86: work around infinite loop in microcode when #AC is delivered Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 57/72] r8169: fix the incorrect tx descriptor version Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 51/72] net:socket: set msg_namelen to 0 if msg_name is passed as NULL in msghdr struct from userland. Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 71/72] x86/mm/hotplug: Pass sync_global_pgds() a correct argument in remove_pagetable() Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:20 +0100
[PATCH 3.12 10/72] power: bq24190_charger: suppress build warning Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 15/72] dm btree: fix leak of bufio-backed block in btree_split_beneath error path Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 35/72] irda: precedence bug in irlmp_seq_hb_idx() Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 22/72] md/raid10: submit_bio_wait() returns 0 on success Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 37/72] ppp: fix pppoe_dev deletion condition in pppoe_release() Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 20/72] crypto: api - Only abort operations on fatal signal Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 27/72] mfd: wm5110: Add register patch for rev D chip Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 21/72] md/raid1: submit_bio_wait() returns 0 on success Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 25/72] serial: 8250_pci: Add support for 16 port Exar boards Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
Re: [PATCH 3.12 25/72] serial: 8250_pci: Add support for 16 port Exar boards Soeren Grunewald <soeren.grunewald@desy.de> - 2015-11-23 15:30 +0100
[PATCH 3.12 32/72] libahci: Allow drivers to override start_engine Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 24/72] IB/cm: Fix rb-tree duplicate free and use-after-free Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 30/72] audit: correctly record file names with different path name types Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 26/72] serial: 8250_pci: Add support for 12 port Exar boards Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 12/72] drm/nouveau/gem: return only valid domain when there's only one Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 39/72] net/mlx4: Copy/set only sizeof struct mlx4_eqe bytes Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 28/72] mfd: wm5110: Add register patch for rev E and above Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 16/72] xhci: handle no ping response error properly Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 18/72] xen-blkfront: check for null drvdata in blkback_changed (XenbusStateClosing) Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 19/72] module: Fix locking in symbol_put_addr() Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 11/72] spi: fix pointer-integer size mismatch warning Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 31/72] audit: create private file name copies when auditing inodes Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 17/72] xhci: Add spurious wakeup quirk for LynxPoint-LP controllers Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 23/72] mvsas: Fix NULL pointer dereference in mvs_slot_task_free Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
[PATCH 3.12 34/72] Fix regression in NFSRDMA server Jiri Slaby <jslaby@suse.cz> - 2015-11-23 14:30 +0100
Re: [PATCH 3.12 34/72] Fix regression in NFSRDMA server Tom Tucker <tom@opengridcomputing.com> - 2015-11-23 16:40 +0100
Re: [PATCH 3.12 00/72] 3.12.51-stable review Guenter Roeck <linux@roeck-us.net> - 2015-11-23 17:30 +0100
Re: [PATCH 3.12 00/72] 3.12.51-stable review Guenter Roeck <linux@roeck-us.net> - 2015-11-23 17:30 +0100
Re: [PATCH 3.12 00/72] 3.12.51-stable review Shuah Khan <shuahkh@osg.samsung.com> - 2015-11-23 17:40 +0100
Re: [PATCH 3.12 00/72] 3.12.51-stable review Guenter Roeck <linux@roeck-us.net> - 2015-11-24 04:50 +0100
Re: [PATCH 3.12 00/72] 3.12.51-stable review Jiri Slaby <jslaby@suse.cz> - 2015-11-30 10:10 +0100
csiph-web