]> git.ipfire.org Git - thirdparty/kernel/linux.git/commit
RISC-V: KVM: Fix shift-out-of-bounds in make_xfence_request()
authorJiakai Xu <xujiakai2025@iscas.ac.cn>
Fri, 3 Apr 2026 23:20:11 +0000 (23:20 +0000)
committerAnup Patel <anup@brainfault.org>
Mon, 6 Apr 2026 04:13:02 +0000 (09:43 +0530)
commitddbf9c76c4020bf63a0799b00faad40caa3de6c2
tree6a3c693d5fbbf1baefed2799a71131f8227447a5
parent7263b4fdb0b240e67e3ebd802e0df761d35a7fdf
RISC-V: KVM: Fix shift-out-of-bounds in make_xfence_request()

The make_xfence_request() function uses a shift operation to check if a
vCPU is in the hart mask:

  if (!(hmask & (1UL << (vcpu->vcpu_id - hbase))))

However, when the difference between vcpu_id and hbase
is >= BITS_PER_LONG, the shift operation causes undefined behavior.

This was detected by UBSAN:
  UBSAN: shift-out-of-bounds in arch/riscv/kvm/tlb.c:343:23
  shift exponent 256 is too large for 64-bit type 'long unsigned int'

Fix this by adding a bounds check before the shift operation.

This bug was found by fuzzing the KVM RISC-V interface.

Fixes: 13acfec2dbcc ("RISC-V: KVM: Add remote HFENCE functions based on VCPU requests")
Signed-off-by: Jiakai Xu <jiakaiPeanut@gmail.com>
Signed-off-by: Jiakai Xu <xujiakai2025@iscas.ac.cn>
Reviewed-by: Andrew Jones <andrew.jones@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260403232011.2394966-1-xujiakai2025@iscas.ac.cn
Signed-off-by: Anup Patel <anup@brainfault.org>
arch/riscv/kvm/tlb.c