]> exis.tech > repos - linux.git/commit
KVM: nVMX: Hide shadow VMCS right after VMCLEAR
authorHyunwoo Kim <imv4bel@gmail.com>
Fri, 17 Jul 2026 10:30:11 +0000 (12:30 +0200)
committerPaolo Bonzini <pbonzini@redhat.com>
Tue, 21 Jul 2026 10:24:49 +0000 (12:24 +0200)
commit622ebfac01ba4f9c0060cebd41257fe46fc4a0b3
treeaea145754df17d136b7bd15f19ac0f7581dd736c
parentfce2dfa773ced15f27dd27cd0b482a7473cdcf2a
KVM: nVMX: Hide shadow VMCS right after VMCLEAR

free_nested() frees the shadow VMCS while vmcs01 still points to it. But
because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU
might migrate before the pointer is cleared and __loaded_vmcs_clear()
may then execute VMCLEAR.

The VMCS needs to stay attached until its explicit VMCLEAR completes, but
then it can be hidden and the page safely freed.

Fixes: 355f4fb1405e ("kvm: nVMX: VMCLEAR an active shadow VMCS after last use")
Cc: stable@vger.kernel.org
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
arch/x86/kvm/vmx/nested.c