| From 82277eeed65eed6c6ee5b8f97bd978763eab148f Mon Sep 17 00:00:00 2001 |
| From: Sean Christopherson <seanjc@google.com> |
| Date: Wed, 21 Apr 2021 19:21:25 -0700 |
| Subject: KVM: nVMX: Truncate base/index GPR value on address calc in !64-bit |
| |
| From: Sean Christopherson <seanjc@google.com> |
| |
| commit 82277eeed65eed6c6ee5b8f97bd978763eab148f upstream. |
| |
| Drop bits 63:32 of the base and/or index GPRs when calculating the |
| effective address of a VMX instruction memory operand. Outside of 64-bit |
| mode, memory encodings are strictly limited to E*X and below. |
| |
| Fixes: 064aea774768 ("KVM: nVMX: Decoding memory operands of VMX instructions") |
| Cc: stable@vger.kernel.org |
| Signed-off-by: Sean Christopherson <seanjc@google.com> |
| Message-Id: <20210422022128.3464144-7-seanjc@google.com> |
| Signed-off-by: Paolo Bonzini <pbonzini@redhat.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| arch/x86/kvm/vmx/nested.c | 4 ++-- |
| 1 file changed, 2 insertions(+), 2 deletions(-) |
| |
| --- a/arch/x86/kvm/vmx/nested.c |
| +++ b/arch/x86/kvm/vmx/nested.c |
| @@ -4639,9 +4639,9 @@ int get_vmx_mem_address(struct kvm_vcpu |
| else if (addr_size == 0) |
| off = (gva_t)sign_extend64(off, 15); |
| if (base_is_valid) |
| - off += kvm_register_read(vcpu, base_reg); |
| + off += kvm_register_readl(vcpu, base_reg); |
| if (index_is_valid) |
| - off += kvm_register_read(vcpu, index_reg) << scaling; |
| + off += kvm_register_readl(vcpu, index_reg) << scaling; |
| vmx_get_segment(vcpu, &s, seg_reg); |
| |
| /* |