Re: [PATCH v2] KVM: guest_memfd: Elaborate on how release() vs. get_pfn() is safe against UAF

From: Sean Christopherson

Date: Thu Sep 24 2026 - 17:57:52 EST


On Wed, 26 Aug 2026 09:56:47 -0700, Sean Christopherson wrote:
> Add more context and information to the comment in kvm_gmem_release() that
> explains why there's no synchronization on RCU _or_ kvm->srcu. Point (b)
> from commit 67b43038ce14 ("KVM: guest_memfd: Remove RCU-protected attribute
> from slot->gmem.file")
>
> b) kvm->srcu ensures that kvm_gmem_unbind() and freeing of a memslot
> occur after the memslot is no longer visible to kvm_gmem_get_pfn().
>
> [...]

Applied to kvm-x86 coco. I'll follow-up with another cleanup for get_pfn() at
some point. Thanks!

[1/1] KVM: guest_memfd: Elaborate on how release() vs. get_pfn() is safe against UAF
https://github.com/kvm-x86/linux/commit/53c34396c19e

--
https://github.com/kvm-x86/linux/tree/next