]> www.infradead.org Git - users/jedix/linux-maple.git/commit
KVM: Ensure all vcpus are consistent with in-kernel irqchip settings
authorAvi Kivity <avi@redhat.com>
Mon, 5 Mar 2012 12:23:29 +0000 (14:23 +0200)
committerMaxim Uvarov <maxim.uvarov@oracle.com>
Wed, 16 May 2012 23:35:18 +0000 (16:35 -0700)
commit6af089c3e1b17c34c0d3226d2ab91ca97b8c50c0
tree207470ba525281b18423e61bb4b968e6d0a0dde9
parentcac725b1df99db21c60e118ffb716a2eabc77c9b
KVM: Ensure all vcpus are consistent with in-kernel irqchip settings

Bugdb: 13871
This fixes: CVE-2012-1601
Commit 3e515705a1f46beb1c942bb8043c16f8ac7b1e9e upstream.
If some vcpus are created before KVM_CREATE_IRQCHIP, then
irqchip_in_kernel() and vcpu->arch.apic will be inconsistent, leading
to potential NULL pointer dereferences.

Fix by:
- ensuring that no vcpus are installed when KVM_CREATE_IRQCHIP is called
- ensuring that a vcpu has an apic if it is installed after KVM_CREATE_IRQCHIP

This is somewhat long winded because vcpu->arch.apic is created without
kvm->lock held.

Based on earlier patch by Michael Ellerman.

Signed-off-by: Michael Ellerman <michael@ellerman.id.au>
Signed-off-by: Avi Kivity <avi@redhat.com>
arch/ia64/kvm/kvm-ia64.c
arch/x86/kvm/x86.c
include/linux/kvm_host.h
virt/kvm/kvm_main.c