| Message ID | 20260403232011.2394966-1-xujiakai2025@iscas.ac.cn |
|---|---|
| State | Accepted |
| Headers | show |
| Series | [v2] RISC-V: KVM: Fix shift-out-of-bounds in make_xfence_request() | expand |
On Fri, Apr 03, 2026 at 11:20:11PM +0000, Jiakai Xu wrote: > The make_xfence_request() function uses a shift operation to check if a > vCPU is in the hart mask: > > if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) > > However, when the difference between vcpu_id and hbase > is >= BITS_PER_LONG, the shift operation causes undefined behavior. > > This was detected by UBSAN: > UBSAN: shift-out-of-bounds in arch/riscv/kvm/tlb.c:343:23 > shift exponent 256 is too large for 64-bit type 'long unsigned int' > > Fix this by adding a bounds check before the shift operation. > > This bug was found by fuzzing the KVM RISC-V interface. > > Fixes: 13acfec2dbcc ("RISC-V: KVM: Add remote HFENCE functions based on VCPU requests") > Signed-off-by: Jiakai Xu <jiakaiPeanut@gmail.com> > Signed-off-by: Jiakai Xu <xujiakai2025@iscas.ac.cn> > --- > V1 -> V2: > - Dropped 'idx' variable and compared vcpu_id against hbase directly, > as suggested by Andrew Jones. > --- > arch/riscv/kvm/tlb.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/arch/riscv/kvm/tlb.c b/arch/riscv/kvm/tlb.c > index ff1aeac4eb8eb..439c20c2775ab 100644 > --- a/arch/riscv/kvm/tlb.c > +++ b/arch/riscv/kvm/tlb.c > @@ -338,7 +338,8 @@ static void make_xfence_request(struct kvm *kvm, > bitmap_zero(vcpu_mask, KVM_MAX_VCPUS); > kvm_for_each_vcpu(i, vcpu, kvm) { > if (hbase != -1UL) { > - if (vcpu->vcpu_id < hbase) > + if (vcpu->vcpu_id < hbase || > + vcpu->vcpu_id >= hbase + BITS_PER_LONG) > continue; > if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) > continue; > -- > 2.34.1 > Reviewed-by: Andrew Jones <andrew.jones@oss.qualcomm.com>
On Sat, Apr 4, 2026 at 4:50 AM Jiakai Xu <xujiakai2025@iscas.ac.cn> wrote: > > The make_xfence_request() function uses a shift operation to check if a > vCPU is in the hart mask: > > if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) > > However, when the difference between vcpu_id and hbase > is >= BITS_PER_LONG, the shift operation causes undefined behavior. > > This was detected by UBSAN: > UBSAN: shift-out-of-bounds in arch/riscv/kvm/tlb.c:343:23 > shift exponent 256 is too large for 64-bit type 'long unsigned int' > > Fix this by adding a bounds check before the shift operation. > > This bug was found by fuzzing the KVM RISC-V interface. > > Fixes: 13acfec2dbcc ("RISC-V: KVM: Add remote HFENCE functions based on VCPU requests") > Signed-off-by: Jiakai Xu <jiakaiPeanut@gmail.com> > Signed-off-by: Jiakai Xu <xujiakai2025@iscas.ac.cn> Queued this patch for Linux-7.1 Thanks, Anup > --- > V1 -> V2: > - Dropped 'idx' variable and compared vcpu_id against hbase directly, > as suggested by Andrew Jones. > --- > arch/riscv/kvm/tlb.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/arch/riscv/kvm/tlb.c b/arch/riscv/kvm/tlb.c > index ff1aeac4eb8eb..439c20c2775ab 100644 > --- a/arch/riscv/kvm/tlb.c > +++ b/arch/riscv/kvm/tlb.c > @@ -338,7 +338,8 @@ static void make_xfence_request(struct kvm *kvm, > bitmap_zero(vcpu_mask, KVM_MAX_VCPUS); > kvm_for_each_vcpu(i, vcpu, kvm) { > if (hbase != -1UL) { > - if (vcpu->vcpu_id < hbase) > + if (vcpu->vcpu_id < hbase || > + vcpu->vcpu_id >= hbase + BITS_PER_LONG) > continue; > if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) > continue; > -- > 2.34.1 >
Hello: This patch was applied to riscv/linux.git (fixes) by Anup Patel <anup@brainfault.org>: On Fri, 3 Apr 2026 23:20:11 +0000 you wrote: > The make_xfence_request() function uses a shift operation to check if a > vCPU is in the hart mask: > > if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) > > However, when the difference between vcpu_id and hbase > is >= BITS_PER_LONG, the shift operation causes undefined behavior. > > [...] Here is the summary with links: - [v2] RISC-V: KVM: Fix shift-out-of-bounds in make_xfence_request() https://git.kernel.org/riscv/c/ddbf9c76c402 You are awesome, thank you!
diff --git a/arch/riscv/kvm/tlb.c b/arch/riscv/kvm/tlb.c index ff1aeac4eb8eb..439c20c2775ab 100644 --- a/arch/riscv/kvm/tlb.c +++ b/arch/riscv/kvm/tlb.c @@ -338,7 +338,8 @@ static void make_xfence_request(struct kvm *kvm, bitmap_zero(vcpu_mask, KVM_MAX_VCPUS); kvm_for_each_vcpu(i, vcpu, kvm) { if (hbase != -1UL) { - if (vcpu->vcpu_id < hbase) + if (vcpu->vcpu_id < hbase || + vcpu->vcpu_id >= hbase + BITS_PER_LONG) continue; if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) continue;
The make_xfence_request() function uses a shift operation to check if a vCPU is in the hart mask: if (!(hmask & (1UL << (vcpu->vcpu_id - hbase)))) However, when the difference between vcpu_id and hbase is >= BITS_PER_LONG, the shift operation causes undefined behavior. This was detected by UBSAN: UBSAN: shift-out-of-bounds in arch/riscv/kvm/tlb.c:343:23 shift exponent 256 is too large for 64-bit type 'long unsigned int' Fix this by adding a bounds check before the shift operation. This bug was found by fuzzing the KVM RISC-V interface. Fixes: 13acfec2dbcc ("RISC-V: KVM: Add remote HFENCE functions based on VCPU requests") Signed-off-by: Jiakai Xu <jiakaiPeanut@gmail.com> Signed-off-by: Jiakai Xu <xujiakai2025@iscas.ac.cn> --- V1 -> V2: - Dropped 'idx' variable and compared vcpu_id against hbase directly, as suggested by Andrew Jones. --- arch/riscv/kvm/tlb.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-)