Skip to content

Commit 83c133c

Browse files
amlutoKAGA-KOKO
authored andcommitted
x86/nmi/64: Fix a paravirt stack-clobbering bug in the NMI code
The NMI entry code that switches to the normal kernel stack needs to be very careful not to clobber any extra stack slots on the NMI stack. The code is fine under the assumption that SWAPGS is just a normal instruction, but that assumption isn't really true. Use SWAPGS_UNSAFE_STACK instead. This is part of a fix for some random crashes that Sasha saw. Fixes: 9b6e6a8 ("x86/nmi/64: Switch stacks on userspace NMI entry") Reported-and-tested-by: Sasha Levin <sasha.levin@oracle.com> Signed-off-by: Andy Lutomirski <luto@kernel.org> Cc: stable@vger.kernel.org Link: http://lkml.kernel.org/r/974bc40edffdb5c2950a5c4977f821a446b76178.1442791737.git.luto@kernel.org Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
1 parent fc57a7c commit 83c133c

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

arch/x86/entry/entry_64.S

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1190,9 +1190,12 @@ ENTRY(nmi)
11901190
* we don't want to enable interrupts, because then we'll end
11911191
* up in an awkward situation in which IRQs are on but NMIs
11921192
* are off.
1193+
*
1194+
* We also must not push anything to the stack before switching
1195+
* stacks lest we corrupt the "NMI executing" variable.
11931196
*/
11941197

1195-
SWAPGS
1198+
SWAPGS_UNSAFE_STACK
11961199
cld
11971200
movq %rsp, %rdx
11981201
movq PER_CPU_VAR(cpu_current_top_of_stack), %rsp

0 commit comments

Comments
 (0)