• Marek Majtyka's avatar
    arm: KVM: Fix incorrect device to IPA mapping · ca09f02f
    Marek Majtyka authored
    A critical bug has been found in device memory stage1 translation for
    VMs with more then 4GB of address space. Once vm_pgoff size is smaller
    then pa (which is true for LPAE case, u32 and u64 respectively) some
    more significant bits of pa may be lost as a shift operation is performed
    on u32 and later cast onto u64.
    
    Example: vm_pgoff(u32)=0x00210030, PAGE_SHIFT=12
            expected pa(u64):   0x0000002010030000
            produced pa(u64):   0x0000000010030000
    
    The fix is to change the order of operations (casting first onto phys_addr_t
    and then shifting).
    Reviewed-by: default avatarMarc Zyngier <marc.zyngier@arm.com>
    [maz: fixed changelog and patch formatting]
    Cc: stable@vger.kernel.org
    Signed-off-by: default avatarMarek Majtyka <marek.majtyka@tieto.com>
    Signed-off-by: default avatarMarc Zyngier <marc.zyngier@arm.com>
    ca09f02f
mmu.c 50.3 KB