[PATCH v2 0/5] KVM: nSVM: Disallow bad L1 EFER for KVM_SET_NESTED_STATE
From: Sean Christopherson
Date: Wed Sep 02 2026 - 19:29:30 EST
Fix a bug where KVM allows userspace to set an impossible EFER for L1 via
KVM_SET_NESTED_STATE, which ultimately can lead to KVM misconfiguring L2's
MMU (yay, NPT!) and overflowing the guest_walker arrays. Then, harden the
MMU against similar bugs (hopefully it works this time; nVMX also had a
similar bug, but the "NPT uses L1's EFER/CR4" wrinkle rendered the existing
hardening useless).
v2:
- Check walker->max_level, not w->cpu_role.base.level, to play nice with PAE
paging on 32-bit hosts. [Sashiko]
- Force EFER.LMA=0 in nested_vmcb02_prepare_save() if EFER.LME=0 to avoid
confusing MMU code.
v1: https://lore.kernel.org/all/20260826211844.884951-2-seanjc@xxxxxxxxxx
Sean Christopherson (5):
KVM: nSVM: Reject KVM_SET_NESTED_STATE if L1 has EFER.LMA=1 &&
EFER.LME=0
KVM: nSVM: Ignore EFER.LMA if EFER.LME=0 when preparing L2 state
KVM: x86/mmu: Bug the VM if KVM attempts to walk more levels than the
MMU has
KVM: x86/mmu: Bug the VM if KVM calcs a CPU role with EFER.LMA=1 &&
CR4.PAE=0
KVM: x86/mmu: Convert MMU walker's bounds check from BUG_ON() to
KVM_BUG_ON()
arch/x86/kvm/mmu/mmu.c | 3 +++
arch/x86/kvm/mmu/paging_tmpl.h | 17 ++++++++++-------
arch/x86/kvm/svm/nested.c | 5 +++++
3 files changed, 18 insertions(+), 7 deletions(-)
base-commit: 76671054f9a1ff6abb976583cd8da37650acdc97
--
2.55.0.970.g62bdec98f9-goog