1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
|
x86/mm: PV superpage handling lacks sanity checks
MMUEXT_{,UN}MARK_SUPER fail to check the input MFN for validity before
dereferencing pointers into the superpage frame table.
get_superpage() has a similar issue.
This is XSA-167.
Reported-by: Qinghao Tang <luodalongde@gmail.com>
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Acked-by: Ian Campbell <ian.campbell@citrix.com>
--- a/xen/arch/x86/mm.c
+++ b/xen/arch/x86/mm.c
@@ -2566,6 +2566,9 @@ int get_superpage(unsigned long mfn, str
ASSERT(opt_allow_superpage);
+ if ( !mfn_valid(mfn | (L1_PAGETABLE_ENTRIES - 1)) )
+ return -EINVAL;
+
spage = mfn_to_spage(mfn);
y = spage->type_info;
do {
@@ -3320,14 +3323,6 @@ long do_mmuext_op(
unsigned long mfn;
struct spage_info *spage;
- mfn = op.arg1.mfn;
- if ( mfn & (L1_PAGETABLE_ENTRIES-1) )
- {
- MEM_LOG("Unaligned superpage reference mfn %lx", mfn);
- okay = 0;
- break;
- }
-
if ( !opt_allow_superpage )
{
MEM_LOG("Superpages disallowed");
@@ -3336,16 +3331,6 @@ long do_mmuext_op(
break;
}
- spage = mfn_to_spage(mfn);
- okay = (mark_superpage(spage, d) >= 0);
- break;
- }
-
- case MMUEXT_UNMARK_SUPER:
- {
- unsigned long mfn;
- struct spage_info *spage;
-
mfn = op.arg1.mfn;
if ( mfn & (L1_PAGETABLE_ENTRIES-1) )
{
@@ -3354,16 +3339,16 @@ long do_mmuext_op(
break;
}
- if ( !opt_allow_superpage )
+ if ( !mfn_valid(mfn | (L1_PAGETABLE_ENTRIES - 1)) )
{
- MEM_LOG("Superpages disallowed");
okay = 0;
- rc = -ENOSYS;
break;
}
spage = mfn_to_spage(mfn);
- okay = (unmark_superpage(spage) >= 0);
+ okay = ((op.cmd == MMUEXT_MARK_SUPER
+ ? mark_superpage(spage, d)
+ : unmark_superpage(spage)) >= 0);
break;
}
|