[PATCH] KVM: arm64: Correctly cap TLBI Range to the architural limit
Wei-Lin Chang
weilin.chang at arm.com
Mon Aug 10 12:00:36 PDT 2026
On Mon, Aug 10, 2026 at 06:06:16PM +0100, Marc Zyngier wrote:
> TLB Invalidation by Range has a fairly powerful way of encoding pretty
> large ranges in a small number of bits. This range can be based on an
> arbitrary VA, which means it is pretty easy for a guest to generate an
> overflow should the hypervisor be naive enough to add the range to the
> base...
>
> Make sure the range is capped to the limit dictated by the address bit
> that determines the VA range. For an IPA invalidation, this is further
> corrected down the line to ignore the upper range.
>
> Fixes: 4ffa72ad8f37e ("KVM: arm64: nv: Add S1 TLB invalidation primitive for VNCR_EL2")
> Reported-by: Wei-Lin Chang <weilin.chang at arm.com>
> Link: https://lore.kernel.org/r/yifz3wn5gk5sr6mapi32trgk5m5kp33bquctsjmkifebnsnndt@fix6u4rthx4g
> Signed-off-by: Marc Zyngier <maz at kernel.org>
> Cc: stable at vger.kernel.org
> ---
> arch/arm64/include/asm/kvm_nested.h | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/arch/arm64/include/asm/kvm_nested.h b/arch/arm64/include/asm/kvm_nested.h
> index c83be6d0e79ac..1ed7083358096 100644
> --- a/arch/arm64/include/asm/kvm_nested.h
> +++ b/arch/arm64/include/asm/kvm_nested.h
> @@ -305,6 +305,12 @@ static inline u64 decode_range_tlbi(u64 val, u64 *range, u16 *asid)
> num = FIELD_GET(GENMASK(43, 39), val);
> *range = __TLBI_RANGE_PAGES(num, scale) << shift;
>
> + /* Cap the range to the correct half of the address space */
> + if (!(base & BIT(48)))
> + *range = min(*range, (BIT(48) - base));
> + else
> + *range = min(*range, ~base + 1);
> +
> return base;
> }
Reviewed-by: Wei-Lin Chang <weilin.chang at arm.com>
>
> --
> 2.47.3
>
More information about the linux-arm-kernel
mailing list