In the Linux kernel, the following vulnerability has been resolved:
x86/mm: Ensure input to pfntokaddr() is treated as a 64-bit type
On 64-bit platforms, the pfntokaddr() macro requires that the input value is 64 bits in order to ensure that valid address bits don't get lost when shifting that input by PAGE_SHIFT to calculate the physical address to provide a virtual address for.
One such example is in pvalidatepages() (used by SEV-SNP guests), where the GFN in the struct used for page-state change requests is a 40-bit bit-field, so attempts to pass this GFN field directly into pfnto_kaddr() ends up causing guest crashes when dealing with addresses above the 1TB range due to the above.
Fix this issue with SEV-SNP guests, as well as any similar cases that might cause issues in current/future code, by using an inline function, instead of a macro, so that the input is implicitly cast to the expected 64-bit input type prior to performing the shift operation.
While it might be argued that the issue is on the caller side, other archs/macros have taken similar approaches to deal with instances like this, such as ARM explicitly casting the input to physaddrt:
e48866647b48 ("ARM: 8396/1: use physaddrt in pfntokaddr()")
A C inline function is even better though.
[ mingo: Refined the changelog some more & added _alwaysinline. ]
{ "vanir_signatures": [ { "signature_type": "Line", "deprecated": false, "signature_version": "v1", "target": { "file": "arch/x86/include/asm/page.h" }, "id": "CVE-2023-52659-38f5d666", "digest": { "line_hashes": [ "59985941995915257408870132178654290450", "57273407679775980394435400285111972143", "231886507218390425545501352867019768984", "114529852027247912527269873937600587229" ], "threshold": 0.9 }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@814305b5c23cb815ada68d43019f39050472b25f" }, { "signature_type": "Line", "deprecated": false, "signature_version": "v1", "target": { "file": "arch/x86/include/asm/page.h" }, "id": "CVE-2023-52659-81aa387e", "digest": { "line_hashes": [ "59985941995915257408870132178654290450", "57273407679775980394435400285111972143", "231886507218390425545501352867019768984", "114529852027247912527269873937600587229" ], "threshold": 0.9 }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8e5647a723c49d73b9f108a8bb38e8c29d3948ea" }, { "signature_type": "Line", "deprecated": false, "signature_version": "v1", "target": { "file": "arch/x86/include/asm/page.h" }, "id": "CVE-2023-52659-aa9d0911", "digest": { "line_hashes": [ "59985941995915257408870132178654290450", "57273407679775980394435400285111972143", "231886507218390425545501352867019768984", "114529852027247912527269873937600587229" ], "threshold": 0.9 }, "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@7e1471888a5e6e846e9b4d306e5327db2b58e64e" } ] }