[PATCH 1/2] KVM: x86: Request event processing for exception VM-Exits

From: Loc Nguyen

Date: Fri Oct 02 2026 - 01:43:17 EST


Request event processing whenever kvm_queue_exception_vmexit() queues an
exception VM-Exit. Most callers reach the helper through
kvm_multiple_exception(), which already sets KVM_REQ_EVENT, but nested
asynchronous page faults call it directly.

Without another event request, vcpu_enter_guest() skips
kvm_check_and_inject_events() and re-enters L2. A subsequent VM-Exit can
clear the pending exception while reconstructing vectoring state, losing
the synthetic #PF VM-Exit. The APF reason remains PAGE_NOT_PRESENT and a
later regular #PF can consume the stale value.

Setting KVM_REQ_EVENT in the common helper ensures that L1 receives the
queued VM-Exit before KVM re-enters L2.

Fixes: 7709aba8f716 ("KVM: x86: Morph pending exceptions to pending VM-Exits at queue time")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Loc Nguyen <loc@xxxxxxxxxx>
---
arch/x86/kvm/x86.c | 2 ++
1 file changed, 2 insertions(+)

diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index cf3fcdfd8ad2..376341a1ba04 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -450,6 +450,8 @@ static void kvm_queue_exception_vmexit(struct kvm_vcpu *vcpu, unsigned int vecto
{
struct kvm_queued_exception *ex = &vcpu->arch.exception_vmexit;

+ kvm_make_request(KVM_REQ_EVENT, vcpu);
+
ex->vector = vector;
ex->injected = false;
ex->pending = true;
--
2.43.0