VMX: values written to MSR_IA32_SYSENTER_E[IS]P should be canonical
authorJan Beulich <jbeulich@suse.com>
Fri, 31 Oct 2014 10:31:11 +0000 (11:31 +0100)
committerJan Beulich <jbeulich@suse.com>
Fri, 31 Oct 2014 10:31:11 +0000 (11:31 +0100)
A recent KVM change by Nadav Amit <namit@cs.technion.ac.il> helped spot
that we have the same issue as they did.

Signed-off-by: Jan Beulich <jbeulich@suse.com>
Reviewed-by: Tim Deegan <tim@xen.org>
Reviewed-by: Andrew Cooper <andrew.cooper3@citrix.com>
Acked-by: Kevin Tian <kevin.tian@intel.com>
xen/arch/x86/hvm/vmx/vmx.c

index 29aaad4a4a7857610adbe34f8277b3f793f427a7..79a69b1d0cf30b703867be234a21cc66fbda0a15 100644 (file)
@@ -2273,9 +2273,13 @@ static int vmx_msr_write_intercept(unsigned int msr, uint64_t msr_content)
         __vmwrite(GUEST_SYSENTER_CS, msr_content);
         break;
     case MSR_IA32_SYSENTER_ESP:
+        if ( !is_canonical_address(msr_content) )
+            goto gp_fault;
         __vmwrite(GUEST_SYSENTER_ESP, msr_content);
         break;
     case MSR_IA32_SYSENTER_EIP:
+        if ( !is_canonical_address(msr_content) )
+            goto gp_fault;
         __vmwrite(GUEST_SYSENTER_EIP, msr_content);
         break;
     case MSR_IA32_DEBUGCTLMSR: {