[PATCH v2 07/10] KVM: WARN and reject guest-based uaccess if VM is dying

From: Sean Christopherson

Date: Thu Oct 01 2026 - 16:25:08 EST


WARN and reject user accesses to guest memory if the associated VM is dying
even if the current address space happens to be the correct address space.
Accessing guest memory after the last reference to the VM has been put may
be "fine" from a safety perspective, but it's still a KVM bug.

Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
---
include/linux/kvm_host.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h
index 2a88e4ce145e..0ee81754d730 100644
--- a/include/linux/kvm_host.h
+++ b/include/linux/kvm_host.h
@@ -1352,7 +1352,8 @@ int kvm_gfn_to_hva_cache_init(struct kvm *kvm, struct gfn_to_hva_cache *ghc,

static __always_inline __must_check bool kvm_can_do_uaccess(struct kvm *kvm)
{
- return !WARN_ON_ONCE(current->mm != kvm->mm);
+ return !WARN_ON_ONCE(current->mm != kvm->mm ||
+ !refcount_read(&kvm->users_count));
}

#define BUILD_KVM_COPY_USER_WRAPPER(fn, to_user, from_user) \
--
2.56.0.rc1.315.gc6ed9934b7-goog