CVE-2011-4622 kvm: pit timer with no irqchip crashes the system (rhbz 771387)
This commit is contained in:
parent
2205c1a917
commit
5dc9ec6f00
69
KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch
Normal file
69
KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch
Normal file
@ -0,0 +1,69 @@
|
||||
From 0924ab2cfa98b1ece26c033d696651fd62896c69 Mon Sep 17 00:00:00 2001
|
||||
From: Jan Kiszka <jan.kiszka@siemens.com>
|
||||
Date: Wed, 14 Dec 2011 19:25:13 +0100
|
||||
Subject: [PATCH] KVM: x86: Prevent starting PIT timers in the absence of
|
||||
irqchip support
|
||||
|
||||
User space may create the PIT and forgets about setting up the irqchips.
|
||||
In that case, firing PIT IRQs will crash the host:
|
||||
|
||||
BUG: unable to handle kernel NULL pointer dereference at 0000000000000128
|
||||
IP: [<ffffffffa10f6280>] kvm_set_irq+0x30/0x170 [kvm]
|
||||
...
|
||||
Call Trace:
|
||||
[<ffffffffa11228c1>] pit_do_work+0x51/0xd0 [kvm]
|
||||
[<ffffffff81071431>] process_one_work+0x111/0x4d0
|
||||
[<ffffffff81071bb2>] worker_thread+0x152/0x340
|
||||
[<ffffffff81075c8e>] kthread+0x7e/0x90
|
||||
[<ffffffff815a4474>] kernel_thread_helper+0x4/0x10
|
||||
|
||||
Prevent this by checking the irqchip mode before starting a timer. We
|
||||
can't deny creating the PIT if the irqchips aren't set up yet as
|
||||
current user land expects this order to work.
|
||||
|
||||
Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
|
||||
Signed-off-by: Marcelo Tosatti <mtosatti@redhat.com>
|
||||
---
|
||||
arch/x86/kvm/i8254.c | 10 +++++++---
|
||||
1 files changed, 7 insertions(+), 3 deletions(-)
|
||||
|
||||
diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c
|
||||
index 76e3f1c..405f262 100644
|
||||
--- a/arch/x86/kvm/i8254.c
|
||||
+++ b/arch/x86/kvm/i8254.c
|
||||
@@ -338,11 +338,15 @@ static enum hrtimer_restart pit_timer_fn(struct hrtimer *data)
|
||||
return HRTIMER_NORESTART;
|
||||
}
|
||||
|
||||
-static void create_pit_timer(struct kvm_kpit_state *ps, u32 val, int is_period)
|
||||
+static void create_pit_timer(struct kvm *kvm, u32 val, int is_period)
|
||||
{
|
||||
+ struct kvm_kpit_state *ps = &kvm->arch.vpit->pit_state;
|
||||
struct kvm_timer *pt = &ps->pit_timer;
|
||||
s64 interval;
|
||||
|
||||
+ if (!irqchip_in_kernel(kvm))
|
||||
+ return;
|
||||
+
|
||||
interval = muldiv64(val, NSEC_PER_SEC, KVM_PIT_FREQ);
|
||||
|
||||
pr_debug("create pit timer, interval is %llu nsec\n", interval);
|
||||
@@ -394,13 +398,13 @@ static void pit_load_count(struct kvm *kvm, int channel, u32 val)
|
||||
/* FIXME: enhance mode 4 precision */
|
||||
case 4:
|
||||
if (!(ps->flags & KVM_PIT_FLAGS_HPET_LEGACY)) {
|
||||
- create_pit_timer(ps, val, 0);
|
||||
+ create_pit_timer(kvm, val, 0);
|
||||
}
|
||||
break;
|
||||
case 2:
|
||||
case 3:
|
||||
if (!(ps->flags & KVM_PIT_FLAGS_HPET_LEGACY)){
|
||||
- create_pit_timer(ps, val, 1);
|
||||
+ create_pit_timer(kvm, val, 1);
|
||||
}
|
||||
break;
|
||||
default:
|
||||
--
|
||||
1.7.6.2
|
||||
|
11
kernel.spec
11
kernel.spec
@ -54,7 +54,7 @@ Summary: The Linux kernel
|
||||
# For non-released -rc kernels, this will be appended after the rcX and
|
||||
# gitX tags, so a 3 here would become part of release "0.rcX.gitX.3"
|
||||
#
|
||||
%global baserelease 2
|
||||
%global baserelease 3
|
||||
%global fedora_build %{baserelease}
|
||||
|
||||
# base_sublevel is the kernel version we're starting with and patching
|
||||
@ -849,6 +849,9 @@ Patch21049: tpm_tis-delay-after-aborting-cmd.patch
|
||||
#rhbz 771006
|
||||
Patch21050: thp-reduce-khugepaged-freezing-latency.patch
|
||||
|
||||
#rhbz 771387
|
||||
Patch21055: KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch
|
||||
|
||||
# compat-wireless patches
|
||||
Patch50000: compat-wireless-config-fixups.patch
|
||||
Patch50001: compat-wireless-change-CONFIG_IWLAGN-CONFIG_IWLWIFI.patch
|
||||
@ -1583,6 +1586,9 @@ ApplyPatch thp-reduce-khugepaged-freezing-latency.patch
|
||||
|
||||
ApplyPatch route-cache-garbage-collector.patch
|
||||
|
||||
#rhbz 771387
|
||||
ApplyPatch KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch
|
||||
|
||||
# END OF PATCH APPLICATIONS
|
||||
|
||||
%endif
|
||||
@ -2358,6 +2364,9 @@ fi
|
||||
# and build.
|
||||
|
||||
%changelog
|
||||
* Tue Jan 03 2012 Josh Boyer <jwboyer@redhat.com>
|
||||
- CVE-2011-4622 kvm: pit timer with no irqchip crashes the system (rhbz 771387)
|
||||
|
||||
* Tue Jan 03 2012 Dave Jones <davej@redhat.com>
|
||||
- thp: reduce khugepaged freezing latency (rhbz 771006)
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user