diff options
author | 2025-04-16 15:26:46 +0000 | |
---|---|---|
committer | 2025-04-28 09:23:46 +0100 | |
commit | 48d848882395a6a42ff1bb685082c79791d4e753 (patch) | |
tree | f2046a22327aead24e47ba3ff468dc0a4b23ecf7 /lib/mpi/mpi-sub-ui.c | |
parent | KVM: arm64: Move hyp state to hyp_vmemmap (diff) | |
download | wireguard-linux-48d848882395a6a42ff1bb685082c79791d4e753.tar.xz wireguard-linux-48d848882395a6a42ff1bb685082c79791d4e753.zip |
KVM: arm64: Defer EL2 stage-1 mapping on share
We currently blindly map into EL2 stage-1 *any* page passed to the
__pkvm_host_share_hyp() HVC. This is less than ideal from a security
perspective as it makes exploitation of potential hypervisor gadgets
easier than it should be. But interestingly, pKVM should never need to
access SHARED_BORROWED pages that it hasn't previously pinned, so there
is no need to map the page before that.
Reviewed-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: Quentin Perret <qperret@google.com>
Link: https://lore.kernel.org/r/20250416152648.2982950-7-qperret@google.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Diffstat (limited to 'lib/mpi/mpi-sub-ui.c')
0 files changed, 0 insertions, 0 deletions