diff options
| author | Yosry Ahmed <yosry@kernel.org> | 2026-07-13 18:01:52 +0000 |
|---|---|---|
| committer | Sean Christopherson <seanjc@google.com> | 2026-07-22 13:42:29 -0700 |
| commit | 184bd464bdb66daa9173670904f24c29c7b7f7d4 (patch) | |
| tree | 19b556f729103e67d103f178fe399218e118efb6 /tools/perf/scripts/python | |
| parent | 92b2af2b6d2c9f53097e48614ea9b9e3aa1dfd43 (diff) | |
KVM: x86: Check EFER validity on KVM_SET_SREGS*
When handling userspace SREGS writes, check the validity of EFER (i.e.
allowed bits) before writing the new value of EFER through the
per-vendor set_efer callbacks. This prevents userspace from writing
bogus values (e.g. EFER.SVME=1 with nested=0).
Note: on KVM_SET_MSRS, KVM only checks EFER validity in terms of KVM
caps, not guest caps, so it is possible to set EFER bits that are
supported by KVM but not by the guest CPUID. Potentially allowing
userspace to set msrs before CPUID.
However, for KVM_SET_SREGS*, check the validity of the set bits against
both KVM and guest caps. This is consistent with other validity checks
(e.g. for CR4) that check validity against guest caps, which already
imposes the need to set CPUID before SREGS.
Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260713180153.2728382-2-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Diffstat (limited to 'tools/perf/scripts/python')
0 files changed, 0 insertions, 0 deletions
