x86/p2m: refuse new allocations for dying domains
authorRoger Pau Monné <roger.pau@citrix.com>
Tue, 11 Oct 2022 12:53:41 +0000 (14:53 +0200)
committerJan Beulich <jbeulich@suse.com>
Tue, 11 Oct 2022 12:53:41 +0000 (14:53 +0200)
commit745e0b300dc3f5000e6d48c273b405d4bcc29ba7
treeb78010a882ec2c73feec3666d825e074af0ec04b
parent28d3f677ec97c98154311f64871ac48762cf980a
x86/p2m: refuse new allocations for dying domains

This will in particular prevent any attempts to add entries to the p2m,
once - in a subsequent change - non-root entries have been removed.

This is part of CVE-2022-33746 / XSA-410.

Signed-off-by: Roger Pau Monné <roger.pau@citrix.com>
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Acked-by: Tim Deegan <tim@xen.org>
master commit: ff600a8cf8e36f8ecbffecf96a035952e022ab87
master date: 2022-10-11 14:23:22 +0200
xen/arch/x86/mm/hap/hap.c
xen/arch/x86/mm/shadow/common.c