[PATCH] RISC-V: KVM: Don't write MMIO load result to x0

Stefan Butz mail at butz.st
Thu Oct 1 00:35:07 PDT 2026


An MMIO load with rd=x0 writes the result into guest_context.zero,
which is never cleared, so later emulated reads of x0 return garbage.

Fixes: 9f7013265112 ("RISC-V: KVM: Handle MMIO exits for VCPU")

Signed-off-by: Stefan Butz <mail at butz.st>
---
An MMIO load with rd=x0 writes the result into guest_context.zero,
which is never cleared, so later emulated reads of x0 return garbage.
---
 arch/riscv/kvm/vcpu_insn.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/arch/riscv/kvm/vcpu_insn.c b/arch/riscv/kvm/vcpu_insn.c
index adbbb59a0f36..2a8dc2b88ba8 100644
--- a/arch/riscv/kvm/vcpu_insn.c
+++ b/arch/riscv/kvm/vcpu_insn.c
@@ -647,7 +647,7 @@ int kvm_riscv_vcpu_mmio_return(struct kvm_vcpu *vcpu, struct kvm_run *run)
 	vcpu->arch.mmio_decode.return_handled = 1;
 	insn = vcpu->arch.mmio_decode.insn;
 
-	if (run->mmio.is_write)
+	if (run->mmio.is_write || !((insn >> SH_RD) & MASK_RX))
 		goto done;
 
 	len = vcpu->arch.mmio_decode.len;

---
base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
change-id: 20261001-b4-mmio_load_protect_x0-5f5fc11ea52a

Best regards,
--  
Stefan Butz <mail at butz.st>




More information about the linux-riscv mailing list