[PATCH] KVM: arm64: Fix the descriptor address in __kvm_at_swap_desc()

Marc Zyngier maz at kernel.org
Tue Mar 17 06:37:57 PDT 2026


On Tue, 17 Mar 2026 11:57:48 +0000,
Zenghui Yu <zenghui.yu at linux.dev> wrote:
> 
> From: "Zenghui Yu (Huawei)" <zenghui.yu at linux.dev>
> 
> Using "(u64 __user *)hva + offset" to get the virtual addresses of S1/S2
> descriptors looks really wrong, if offset is not zero. What we want to get
> for swapping is hva + offset, not hva + offset*8. ;-)
> 
> Fix it.
> 
> Fixes: f6927b41d573 ("KVM: arm64: Add helper for swapping guest descriptor")
> Signed-off-by: Zenghui Yu (Huawei) <zenghui.yu at linux.dev>
> ---
>  arch/arm64/kvm/at.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/arch/arm64/kvm/at.c b/arch/arm64/kvm/at.c
> index c5c5644b1878..a024d9a770dc 100644
> --- a/arch/arm64/kvm/at.c
> +++ b/arch/arm64/kvm/at.c
> @@ -1753,7 +1753,7 @@ int __kvm_at_swap_desc(struct kvm *kvm, gpa_t ipa, u64 old, u64 new)
>  	if (!writable)
>  		return -EPERM;
>  
> -	ptep = (u64 __user *)hva + offset;
> +	ptep = (void __user *)hva + offset;
>  	if (cpus_have_final_cap(ARM64_HAS_LSE_ATOMICS))
>  		r = __lse_swap_desc(ptep, old, new);
>  	else

Holy crap! How did we miss that???

Thanks a lot for spotting it, I'll queue that now.

	M.

-- 
Without deviation from the norm, progress is not possible.



More information about the linux-arm-kernel mailing list