[GIT PULL] KVM: x86: Fixes for 7.3-rc6+
From: Sean Christopherson
Date: Fri Oct 02 2026 - 12:48:48 EST
Please pull a few more fixes. These aren't _that_ urgent, so feel free to
punt these to 7.4 if you think we're throwing too much into late RCs.
That said, I'd really like to get the AVIC fix into 7.3 as I very deliberately
didn't tag it for stable@. The fix depends on what ended up being the changes
to hold kvm->lock for all of vCPU creation, which I don't really want to
encourage folks to backport to LTS kernels. So, if we squeak the AVIC fix
into 7.3, which is presumably the next LTS, we'll save a one-off backport.
Thanks!
The following changes since commit 973ea70393e885e540f714904e51bc6cac80e3d7:
KVM: SEV: Do cache maintenance on the source VM *before* clearing SEV state (2026-09-28 17:11:49 -0400)
are available in the Git repository at:
https://github.com/kvm-x86/linux.git tags/kvm-x86-fixes-7.3-rc6
for you to fetch changes up to b3e6212dea2e4328a841ceb37f377583176dc735:
KVM: x86: Use active memslots for the per-vCPU MMIO cache (2026-09-30 06:40:49 -0700)
----------------------------------------------------------------
KVM x86 fixed for 7.3-rcN
- If creating a vCPU ultimately fails, clear its entry in the AVIC Physical ID
table used by hardware to perform IPI Virtualization and delivered posted
IRQs. I.e. plug the same use-after-free hole related to IPI virtualization
and posted IRQs that was fixed for APICv by commit b41f2ca6c0601 ("KVM: VMX:
Fix stale PID-pointer table entry left after vCPU free").
- Use set_page_dirty_lock() instead of set_page_dirty() when marking a page
dirty after writing back SNP firmware's desired CPUID state to userspace.
Using set_page_dirty() is unsafe if the page/folio isn't locked (as pointed
out by its function comment's big DANGER warning, which no one reads given
the number of bugs of this exact nature).
- When checking for an MMIO generation match, use the memslots for the current
vCPU context (non-SMM vs. SMM), as a misbehaving guest can coerce KVM into
incorrectly identifying a write as MMIO in order to bypass KVM's
write-tracking.
----------------------------------------------------------------
Jann Horn (1):
KVM: SEV: Fix page dirtying in sev_gmem_post_populate()
Jinu Kim (1):
KVM: x86: Use active memslots for the per-vCPU MMIO cache
Naveen N Rao (AMD) (1):
KVM: SVM: Clear AVIC Physical ID table entry if vCPU creation fails
Sean Christopherson (2):
KVM: SVM: Add paranoid helper for checking if vCPU is AVIC-addressable
KVM: SVM: Use "is AVIC-addressable" helper to sanity check load()/put()
arch/x86/kvm/svm/avic.c | 22 ++++++++++++++++------
arch/x86/kvm/svm/sev.c | 2 +-
arch/x86/kvm/svm/svm.c | 6 +++++-
arch/x86/kvm/svm/svm.h | 1 +
arch/x86/kvm/x86.h | 4 ++--
5 files changed, 25 insertions(+), 10 deletions(-)