From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C80A3511E8A for ; Mon, 21 Sep 2026 21:16:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790025374; cv=none; b=HaruKxMm2qR/c2/gwbfPXFBsqIOg7ak0gol04LXKqRUMaqSgXED3pqlSQKbAphAR0yLI7RLWZ5wxVtVSncgJtdUNXeBI87GuiDPiVA/VOLyA4k/ywocFdLLRV/PkjmNnJ2dAh2t0GaabBLsaO+Ztuuob72fdMKfrjBqZ1eubsxQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790025374; c=relaxed/simple; bh=pRV+4Yz/MRvphetpcx2XfsYCtav+An9pfXk6M+2KL+E=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=cjGssFWUW0o5cE0wwTBOL17kaf6Zb5jKWAG04mmKps8ZiHpCuVl98V+8JoNqrtMTNtkUR7X0VhkNREOXESeyvjaK2lgjO+SStlazZBqt6jgY7u7UnJjd0IPblMRX4LodRleG0XYdoBc5+uCB2JPnpo1/mIyLQVG31AF5fail44I= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=nYHmB6PT; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nYHmB6PT" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-39512608fb1so8225901a91.1 for ; Mon, 21 Sep 2026 14:16:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790025372; x=1790630172; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cljxKoEkJHuB8e5gB97za3SJLDV8TCYQCWMWqDIf1FI=; b=nYHmB6PT8s6j2TfY+J6qs2bNq7T2p3V+fTw0BRpknmD28vIzwmOZnseQXu3L67iD/y Bl/dYv2SHg78sy4J6xcva9d93tg8NKfp1Kev52JGXFn7oxntcTgIur0pUG8SIyJIFEIW 6IYdN4UhQLww5KFA1cGtXiHfWSKZMVyQdqgwi8fR/4YoJrHAoHHAddIvij8SbELux5LH g2LeWyToXTkDP3Q9H6IjthX3pPYZQWwYMJLnlVapahFXEQ1p0G6lfI64CHV4eDh0Kph+ AzTfyYzOp7vJ/MkiT4eBpES0/w+EU43zk1ARxrvEZMOqTKevQmfeetdzOgwbUDdkPKtk j2qQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790025372; x=1790630172; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=cljxKoEkJHuB8e5gB97za3SJLDV8TCYQCWMWqDIf1FI=; b=wuxXDemuotYv+g/1VR19fnsxEcu0fHttJovVDeAAx1FTkb1JkVnRKZPaASzPeG3pdw wxy5OUCxJ+ohUrP6uORQWThZ3NyrCsthH5KCNVNPju6hNsfucJcPkVoyg9tGpoZWTCPX 2tTIxq5nr6vFc4+zXk4lSdTVr+Dw3H4+C/PLcd4GCBX0bB5FBTTH5v4pHM7jD3YK3gHQ 1d/6xY/isd2xLLGKGe/17E0Oy+wVQHnZVINYdKlXgB4E+LD45vZPnQVY2ycy+a1pVLpc l3oWoW0rsS13iJQLnM5pfEakFIaJJ1uGIGDVO05v5DRUe16+EyamZWyHjX9uvx+jl7nI 2LLw== X-Forwarded-Encrypted: i=1; AKwUvBygV+AFOhA227GyUl4Iuxt2oxNMMjIEEDrjuxUGp/kKwJBEBmQjIhvJz/GwvaLQ4i5aa6yQ1kmLbAHVixE=@vger.kernel.org X-Gm-Message-State: AFuF++mAGKBGtFuhTF7UrvDNqzEALWeIE8qFCLOF+zUSh1Fwg6usyUN+ +sAoF+Dt4LmY8SgmuSYWEgU5ZAJiFjsa8EZs0J58lwxLfXoPWduiQMtIB9M0mKq+W2nCyCXypGy XAhAmCw== X-Received: from pjqx12.prod.google.com ([2002:a17:90a:b00c:b0:3a0:525a:e19f]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:39ad:b0:39e:6c69:9b95 with SMTP id 98e67ed59e1d1-39e6c69b29dmr10920170a91.58.1790025371869; Mon, 21 Sep 2026 14:16:11 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 21 Sep 2026 14:16:07 -0700 In-Reply-To: <20260921211608.1030158-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921211608.1030158-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921211608.1030158-2-seanjc@google.com> Subject: [PATCH v2 1/2] KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jinwoo Lee , Stefan Teodorescu Content-Type: text/plain; charset="UTF-8" Re-pend GET_NESTED_STATE_PAGES before exiting to userspace if getting the nested pages fails in the KVM_RUN path. If userspace re-runs the vCPU, and vmcs02 holds valid PFNs from the *previous* run of L2, then KVM could re-enter L2 with stale, unpinned PFNs mapped into e.g. the vAPIC page. Note, both SVM and VMX (as of commit 11722439fb20 ("KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit") ensure the request is cleared on VM-Exit (including the "forced" case), i.e. there is no risk of double-mapping due to emulated VMLAUNCH/VMRESUME/VMRUN *and* the request trying to map the nested pages. Fixes: 671ddc700fd0 ("KVM: nVMX: Don't leak L1 MMIO regions to L2") Cc: stable@vger.kernel.org Reported-by: Jinwoo Lee Closes: https://lore.kernel.org/all/20260813043932.3214460-1-rkskek9254@gmail.com Reported-by: Stefan Teodorescu Signed-off-by: Sean Christopherson --- arch/x86/kvm/x86.c | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index af3ceee714c9..3c5d3e19ec99 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -8024,6 +8024,7 @@ static int vcpu_enter_guest(struct kvm_vcpu *vcpu) if (kvm_check_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu)) { if (unlikely(!kvm_nested_call(get_nested_state_pages)(vcpu))) { + kvm_make_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu); r = 0; goto out; } -- 2.55.0.1082.g2b9226bbc0-goog