From 5dc9ec6f005c484c538cf8e18ceccd90f479f46a Mon Sep 17 00:00:00 2001 From: Josh Boyer Date: Tue, 3 Jan 2012 10:27:26 -0500 Subject: [PATCH] CVE-2011-4622 kvm: pit timer with no irqchip crashes the system (rhbz 771387) --- ...tarting-PIT-timers-in-the-absence-of.patch | 69 +++++++++++++++++++ kernel.spec | 11 ++- 2 files changed, 79 insertions(+), 1 deletion(-) create mode 100644 KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch diff --git a/KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch b/KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch new file mode 100644 index 000000000..07ef3e71b --- /dev/null +++ b/KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch @@ -0,0 +1,69 @@ +From 0924ab2cfa98b1ece26c033d696651fd62896c69 Mon Sep 17 00:00:00 2001 +From: Jan Kiszka +Date: Wed, 14 Dec 2011 19:25:13 +0100 +Subject: [PATCH] KVM: x86: Prevent starting PIT timers in the absence of + irqchip support + +User space may create the PIT and forgets about setting up the irqchips. +In that case, firing PIT IRQs will crash the host: + +BUG: unable to handle kernel NULL pointer dereference at 0000000000000128 +IP: [] kvm_set_irq+0x30/0x170 [kvm] +... +Call Trace: + [] pit_do_work+0x51/0xd0 [kvm] + [] process_one_work+0x111/0x4d0 + [] worker_thread+0x152/0x340 + [] kthread+0x7e/0x90 + [] kernel_thread_helper+0x4/0x10 + +Prevent this by checking the irqchip mode before starting a timer. We +can't deny creating the PIT if the irqchips aren't set up yet as +current user land expects this order to work. + +Signed-off-by: Jan Kiszka +Signed-off-by: Marcelo Tosatti +--- + arch/x86/kvm/i8254.c | 10 +++++++--- + 1 files changed, 7 insertions(+), 3 deletions(-) + +diff --git a/arch/x86/kvm/i8254.c b/arch/x86/kvm/i8254.c +index 76e3f1c..405f262 100644 +--- a/arch/x86/kvm/i8254.c ++++ b/arch/x86/kvm/i8254.c +@@ -338,11 +338,15 @@ static enum hrtimer_restart pit_timer_fn(struct hrtimer *data) + return HRTIMER_NORESTART; + } + +-static void create_pit_timer(struct kvm_kpit_state *ps, u32 val, int is_period) ++static void create_pit_timer(struct kvm *kvm, u32 val, int is_period) + { ++ struct kvm_kpit_state *ps = &kvm->arch.vpit->pit_state; + struct kvm_timer *pt = &ps->pit_timer; + s64 interval; + ++ if (!irqchip_in_kernel(kvm)) ++ return; ++ + interval = muldiv64(val, NSEC_PER_SEC, KVM_PIT_FREQ); + + pr_debug("create pit timer, interval is %llu nsec\n", interval); +@@ -394,13 +398,13 @@ static void pit_load_count(struct kvm *kvm, int channel, u32 val) + /* FIXME: enhance mode 4 precision */ + case 4: + if (!(ps->flags & KVM_PIT_FLAGS_HPET_LEGACY)) { +- create_pit_timer(ps, val, 0); ++ create_pit_timer(kvm, val, 0); + } + break; + case 2: + case 3: + if (!(ps->flags & KVM_PIT_FLAGS_HPET_LEGACY)){ +- create_pit_timer(ps, val, 1); ++ create_pit_timer(kvm, val, 1); + } + break; + default: +-- +1.7.6.2 + diff --git a/kernel.spec b/kernel.spec index 822afc33c..7b3869cca 100644 --- a/kernel.spec +++ b/kernel.spec @@ -54,7 +54,7 @@ Summary: The Linux kernel # For non-released -rc kernels, this will be appended after the rcX and # gitX tags, so a 3 here would become part of release "0.rcX.gitX.3" # -%global baserelease 2 +%global baserelease 3 %global fedora_build %{baserelease} # base_sublevel is the kernel version we're starting with and patching @@ -849,6 +849,9 @@ Patch21049: tpm_tis-delay-after-aborting-cmd.patch #rhbz 771006 Patch21050: thp-reduce-khugepaged-freezing-latency.patch +#rhbz 771387 +Patch21055: KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch + # compat-wireless patches Patch50000: compat-wireless-config-fixups.patch Patch50001: compat-wireless-change-CONFIG_IWLAGN-CONFIG_IWLWIFI.patch @@ -1583,6 +1586,9 @@ ApplyPatch thp-reduce-khugepaged-freezing-latency.patch ApplyPatch route-cache-garbage-collector.patch +#rhbz 771387 +ApplyPatch KVM-x86-Prevent-starting-PIT-timers-in-the-absence-of.patch + # END OF PATCH APPLICATIONS %endif @@ -2358,6 +2364,9 @@ fi # and build. %changelog +* Tue Jan 03 2012 Josh Boyer +- CVE-2011-4622 kvm: pit timer with no irqchip crashes the system (rhbz 771387) + * Tue Jan 03 2012 Dave Jones - thp: reduce khugepaged freezing latency (rhbz 771006)