Re: [PATCH 1/2] LoongArch: KVM: EIOINTC: clamp ipnum to valid range in INT_ENCODE mode
From: Tao Cui
Date: Mon Jul 13 2026 - 23:19:39 EST
在 2026/7/14 10:32, Bibo Mao 写道:
> Hi Tao,
>
> Thanks to catch this, there is similar modification which can be located at:
> https://lore.kernel.org/lkml/20260709082109.1361767-5-maobibo@xxxxxxxxxxx/
>
Hi Bibo,
Haha, looks like we raced to the same fix :) I came across it while
debugging VM migration (the LOAD_FINISHED restore path). Your patch
takes priority — I'll go ahead and drop my series.
Thanks,
Tao
> Regards
> Bibo Mao
>
> On 2026/7/14 上午9:24, Tao Cui wrote:
>> From: Tao Cui <cuitao@xxxxxxxxxx>
>>
>> The IP-number decode in eiointc_set_sw_coreisr() and eiointc_update_irq()
>> clamps ipnum only in the default (1-hot) mode. In INT_ENCODE mode the raw
>> ipmap byte (0..255) is used as the index into sw_coreisr[cpu][ipnum],
>> whose second dimension is LOONGSON_IP_NUM (8), so any ipmap byte >= 8
>> accesses the array out of bounds.
>>
>> The value is guest-programmable through the EIOINTC virtual extension
>> (VIRT_CONFIG enables INT_ENCODE and the IPMAP IOCSR write is unvalidated)
>> and is also restored unvalidated from a migration stream via the
>> LOAD_FINISHED control attribute, resulting in a host slab out-of-bounds
>> access reachable from an unprivileged guest.
>>
>> Clamp ipnum to [0, LOONGSON_IP_NUM) in INT_ENCODE mode as well.
>>
>> Fixes: 3956a52bc05b ("LoongArch: KVM: Add EIOINTC read and write functions")
>> Cc: stable@xxxxxxxxxxxxxxx
>> Signed-off-by: Tao Cui <cuitao@xxxxxxxxxx>
>> ---
>> arch/loongarch/kvm/intc/eiointc.c | 4 ++++
>> 1 file changed, 4 insertions(+)
>>
>> diff --git a/arch/loongarch/kvm/intc/eiointc.c b/arch/loongarch/kvm/intc/eiointc.c
>> index 2b14485d14a7..0c34d7ab264d 100644
>> --- a/arch/loongarch/kvm/intc/eiointc.c
>> +++ b/arch/loongarch/kvm/intc/eiointc.c
>> @@ -17,6 +17,8 @@ static void eiointc_set_sw_coreisr(struct loongarch_eiointc *s)
>> if (!(s->status & BIT(EIOINTC_ENABLE_INT_ENCODE))) {
>> ipnum = count_trailing_zeros(ipnum);
>> ipnum = ipnum < 4 ? ipnum : 0;
>> + } else {
>> + ipnum = (ipnum < LOONGSON_IP_NUM) ? ipnum : 0;
>> }
>> cpuid = ((u8 *)s->coremap)[irq];
>> @@ -42,6 +44,8 @@ static void eiointc_update_irq(struct loongarch_eiointc *s, int irq, int level)
>> if (!(s->status & BIT(EIOINTC_ENABLE_INT_ENCODE))) {
>> ipnum = count_trailing_zeros(ipnum);
>> ipnum = ipnum < 4 ? ipnum : 0;
>> + } else {
>> + ipnum = (ipnum < LOONGSON_IP_NUM) ? ipnum : 0;
>> }
>> cpu = s->sw_coremap[irq];
>>
>