summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMarc Zyngier <marc.zyngier@arm.com>2016-07-17 14:00:49 +0200
committerMarc Zyngier <marc.zyngier@arm.com>2016-07-18 19:15:17 +0200
commit333a53ff7fb9d836ff4a2b7f266ac9b2bb85e873 (patch)
treeb1a56c97b9322ce5ca31307e00b2beac7abbfa53
parentKVM: arm64: vgic-its: Fix misleading nr_entries in vgic_its_check_device_id (diff)
downloadlinux-333a53ff7fb9d836ff4a2b7f266ac9b2bb85e873.tar.xz
linux-333a53ff7fb9d836ff4a2b7f266ac9b2bb85e873.zip
KVM: arm64: vgic-its: Validate the device table L1 entry
Checking that the device_id fits if the table, and we must make sure that the associated memory is also accessible. Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
-rw-r--r--virt/kvm/arm/vgic/vgic-its.c13
1 files changed, 11 insertions, 2 deletions
diff --git a/virt/kvm/arm/vgic/vgic-its.c b/virt/kvm/arm/vgic/vgic-its.c
index 268a0c7ea3a5..4943d6aebdd1 100644
--- a/virt/kvm/arm/vgic/vgic-its.c
+++ b/virt/kvm/arm/vgic/vgic-its.c
@@ -693,8 +693,17 @@ static bool vgic_its_check_device_id(struct kvm *kvm, struct vgic_its *its,
gfn_t gfn;
- if (!(r & GITS_BASER_INDIRECT))
- return device_id < (l1_tbl_size / GITS_BASER_ENTRY_SIZE(r));
+ if (!(r & GITS_BASER_INDIRECT)) {
+ phys_addr_t addr;
+
+ if (device_id >= (l1_tbl_size / GITS_BASER_ENTRY_SIZE(r)))
+ return false;
+
+ addr = BASER_ADDRESS(r) + device_id * GITS_BASER_ENTRY_SIZE(r);
+ gfn = addr >> PAGE_SHIFT;
+
+ return kvm_is_visible_gfn(kvm, gfn);
+ }
/* calculate and check the index into the 1st level */
index = device_id / (SZ_64K / GITS_BASER_ENTRY_SIZE(r));