KVM: arm64: vgic-its: Validate the device table L1 entry

Checking that the device_id fits if the table, and we must make
sure that the associated memory is also accessible.

Signed-off-by: Marc Zyngier <marc.zyngier@arm.com>
This commit is contained in:
Marc Zyngier 2016-07-17 13:00:49 +01:00
parent b90338b7cb
commit 333a53ff7f
1 changed files with 11 additions and 2 deletions

View File

@ -693,8 +693,17 @@ static bool vgic_its_check_device_id(struct kvm *kvm, struct vgic_its *its,
gfn_t gfn;
if (!(r & GITS_BASER_INDIRECT))
return device_id < (l1_tbl_size / GITS_BASER_ENTRY_SIZE(r));
if (!(r & GITS_BASER_INDIRECT)) {
phys_addr_t addr;
if (device_id >= (l1_tbl_size / GITS_BASER_ENTRY_SIZE(r)))
return false;
addr = BASER_ADDRESS(r) + device_id * GITS_BASER_ENTRY_SIZE(r);
gfn = addr >> PAGE_SHIFT;
return kvm_is_visible_gfn(kvm, gfn);
}
/* calculate and check the index into the 1st level */
index = device_id / (SZ_64K / GITS_BASER_ENTRY_SIZE(r));