Re: [PATCH] mshv: bounds-check cpu index in vtl mmap fault handler

From: Wei Liu

Date: Thu Jul 23 2026 - 13:12:28 EST


On Thu, Jul 23, 2026 at 02:37:51PM +0530, Naman Jain wrote:
>
>
> On 7/9/2026 7:49 AM, Yi Xie wrote:
> > cpu is taken from pgoff & 0xffff. cpu_online() does not reject cpu >=
> > nr_cpu_ids, and per_cpu_ptr() can then walk off __per_cpu_offset.
> >
> > Signed-off-by: Yi Xie <xieyi@xxxxxxxxxx>
> > ---
> > drivers/hv/mshv_vtl_main.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/hv/mshv_vtl_main.c b/drivers/hv/mshv_vtl_main.c
> > index 0d3d4161974f..fc50c44ac1bd 100644
> > --- a/drivers/hv/mshv_vtl_main.c
> > +++ b/drivers/hv/mshv_vtl_main.c
> > @@ -801,7 +801,7 @@ static vm_fault_t mshv_vtl_fault(struct vm_fault *vmf)
> > int cpu = vmf->pgoff & MSHV_PG_OFF_CPU_MASK;
> > int real_off = vmf->pgoff >> MSHV_REAL_OFF_SHIFT;
> > - if (!cpu_online(cpu))
> > + if (cpu >= nr_cpu_ids || !cpu_online(cpu))
> > return VM_FAULT_SIGBUS;
> > /*
> > * CPU Hotplug is not supported in VTL2 in OpenHCL, where this kernel driver exists.
>
> The problem fixed by this patch generally does not happen in practice as the
> user space is trusted user space (OpenVMM). Nevertheless, it's good to have
> this check.
>
> Nit: subject - s/"mshv:"/"mshv_vtl:"
> as this was the agreed upon prefix for changes to mshv_vtl_main driver.
>
> Reviewed-by: Naman Jain <namjain@xxxxxxxxxxxxxxxxxxx>

Thank you. Applied.