[PATCH v3 02/21] KVM: SVM: Fallback to the default TSC ratio if KVM tries to use a bad multiplier

From: Sean Christopherson

Date: Wed Sep 30 2026 - 13:56:23 EST


Explicitly WARN and fallback to the default TSC ratio, i.e. run the guest
at L0's TSC frequency, if KVM tries to program a bad multiplier value. As
pointed out by Sashiko, leaving the MSR as-is bleeds state from the vCPU
that last ran on the pCPU into the likely-misbehaving current vCPU.

Leaking a vCPU's frequency isn't very interesting, and corrupting KVM's
cache isn't a big deal either since KVM would only refuse to try to write
the same bad value in the future, but falling back to the default value is
trivial, and explicitly WARNing ensures a KVM bug won't slip by silently.

E.g. because ex_handler_msr() only WARNs once for *all* WRMSRs, it's
possible for the potentially-fatal-to-the-guest issue to not exhibit any
visible symptoms in the host.

Reported-by: Sashiko Bot <sashiko-bot@xxxxxxxxxx>
Closes: https://lore.kernel.org/all/20260722091414.E842B1F000E9@xxxxxxxxxxxxxxx
Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
---
arch/x86/kvm/svm/svm.c | 9 +++++++++
1 file changed, 9 insertions(+)

diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
index 0eb1623052c1..2b6888417bc0 100644
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -533,6 +533,15 @@ static int svm_check_processor_compat(void)

static void __svm_write_tsc_multiplier(u64 multiplier)
{
+ /*
+ * Fallback to the default ratio if KVM is buggy and tries to program
+ * an unsupported scaling ratio, e.g. so that the guest has a chance of
+ * surviving, so that the cache isn't stale/corrupted, and so that KVM
+ * doesn't leak state across VMs.
+ */
+ if (WARN_ON_ONCE(multiplier & SVM_TSC_RATIO_RSVD))
+ multiplier = SVM_TSC_RATIO_DEFAULT;
+
if (multiplier == __this_cpu_read(current_tsc_ratio))
return;

--
2.56.0.rc1.315.gc6ed9934b7-goog