|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [xen stable-4.18] x86/vrtc: fix race in CMOS index checking
commit eb666059f0b0e1642cdbae7d05e9884699d0e3c2
Author: Roger Pau Monne <roger.pau@xxxxxxxxxx>
AuthorDate: Wed Jul 15 12:44:37 2026 +0200
Commit: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
CommitDate: Tue Jul 28 13:10:03 2026 +0100
x86/vrtc: fix race in CMOS index checking
Do the checking for a valid CMOS index while holding the spinlock,
otherwise the value could be changed by the guest after having been
checked.
This is XSA-503 / CVE-2026-62430.
Fixes: 34bef0e6d5f4 ("hvm: Add locking to platform timers.")
Signed-off-by: Roger Pau Monné <roger.pau@xxxxxxxxxx>
Reviewed-by: Jan Beulich <jbeulich@xxxxxxxx>
(cherry picked from commit 52350da92619a77472ebb87f20f6a1fea49eebfd)
---
xen/arch/x86/hvm/rtc.c | 21 ++++++++++++++-------
1 file changed, 14 insertions(+), 7 deletions(-)
diff --git a/xen/arch/x86/hvm/rtc.c b/xen/arch/x86/hvm/rtc.c
index 4839374352..ad15825a1f 100644
--- a/xen/arch/x86/hvm/rtc.c
+++ b/xen/arch/x86/hvm/rtc.c
@@ -647,16 +647,24 @@ static int update_in_progress(RTCState *s)
return 0;
}
-static uint32_t rtc_ioport_read(RTCState *s, uint32_t addr)
+static bool rtc_ioport_read(RTCState *s, uint32_t addr, uint32_t *val)
{
int ret;
struct domain *d = vrtc_domain(s);
+ *val = ~0;
+
if ( (addr & 1) == 0 )
- return 0xff;
+ return true;
spin_lock(&s->lock);
+ if ( s->hw.cmos_index >= RTC_CMOS_SIZE )
+ {
+ spin_unlock(&s->lock);
+ return false;
+ }
+
switch ( s->hw.cmos_index )
{
case RTC_SECONDS:
@@ -696,7 +704,9 @@ static uint32_t rtc_ioport_read(RTCState *s, uint32_t addr)
spin_unlock(&s->lock);
- return ret;
+ *val = ret;
+
+ return true;
}
static int cf_check handle_rtc_io(
@@ -716,11 +726,8 @@ static int cf_check handle_rtc_io(
if ( rtc_ioport_write(vrtc, port, (uint8_t)*val) )
return X86EMUL_OKAY;
}
- else if ( vrtc->hw.cmos_index < RTC_CMOS_SIZE )
- {
- *val = rtc_ioport_read(vrtc, port);
+ else if ( rtc_ioport_read(vrtc, port, val) )
return X86EMUL_OKAY;
- }
return X86EMUL_UNHANDLEABLE;
}
--
generated by git-patchbot for /home/xen/git/xen.git#stable-4.18
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |