[PATCH v2 3/4] KVM: arm64: vgic: Reject out-of-range GICv5 PPI IDs

Joey Gouly joey.gouly at arm.com
Wed Aug 12 05:56:27 PDT 2026


On Tue, Aug 11, 2026 at 03:11:18PM +0000, Sascha Bischoff wrote:
> GICv5 supports up to 128 PPIs, but KVM currently implements only the
> first 64, which contain the architected PPIs it supports.
> 
> An encoded PPI with an ID outside that range passes irq_is_ppi(),
> which only checks the encoded interrupt type. vgic_get_vcpu_irq()
> therefore looks it up in private_irqs[], where array_index_nospec()
> clamps the out-of-range index to zero and aliases PPI 0.
> 
> Include the supported PPI range in irq_is_ppi() so that KVM interfaces
> reject unsupported PPIs. Also reject an out-of-range PPI in the lookup
> as a safeguard against callers bypassing the predicate.
> 
> Fixes: 4d591252bacb ("KVM: arm64: gic-v5: Implement PPI interrupt injection")
> Fixes: eb8bce08ecb1 ("KVM: arm64: gic: Introduce interrupt type helpers")
> Link: https://sashiko.dev/#/patchset/20260724104819.1296803-1-sascha.bischoff@arm.com?part=27
> Signed-off-by: Sascha Bischoff <sascha.bischoff at arm.com>
> ---
>  arch/arm64/kvm/vgic/vgic.c | 2 ++
>  include/kvm/arm_vgic.h     | 2 ++
>  2 files changed, 4 insertions(+)
> 
> diff --git a/arch/arm64/kvm/vgic/vgic.c b/arch/arm64/kvm/vgic/vgic.c
> index 352d52bd6315c..b25303d9919fd 100644
> --- a/arch/arm64/kvm/vgic/vgic.c
> +++ b/arch/arm64/kvm/vgic/vgic.c
> @@ -118,6 +118,8 @@ struct vgic_irq *vgic_get_vcpu_irq(struct kvm_vcpu *vcpu, u32 intid)
>  		switch (type) {
>  		case KVM_DEV_TYPE_ARM_VGIC_V5:
>  			intid = vgic_v5_get_hwirq_id(intid);
> +			if (intid >= VGIC_V5_NR_PRIVATE_IRQS)
> +				return NULL;
>  			intid = array_index_nospec(intid, VGIC_V5_NR_PRIVATE_IRQS);
>  			break;
>  		default:
> diff --git a/include/kvm/arm_vgic.h b/include/kvm/arm_vgic.h
> index cefddc9c621de..1a549cceecbec 100644
> --- a/include/kvm/arm_vgic.h
> +++ b/include/kvm/arm_vgic.h
> @@ -65,6 +65,8 @@
>  		switch (t) {						\
>  		case KVM_DEV_TYPE_ARM_VGIC_V5:				\
>  			__ret = is_v5_type(GICV5_HWIRQ_TYPE_PPI, (i));	\
> +			__ret &= FIELD_GET(GICV5_HWIRQ_ID, (i)) <	\
> +				 VGIC_V5_NR_PRIVATE_IRQS;		\
>  			break;						\
>  		default:						\
>  			__ret  = (i) >= VGIC_NR_SGIS;			\

Reviewed-by: Joey Gouly <joey.gouly at arm.com>



More information about the linux-arm-kernel mailing list