KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state
Published Apr 8, 2025
7.3
HIGHCVSS 3.1
EPSS 0.21%
Description
There are several problems with the way hyp code lazily saves the host's FPSIMD/SVE state, including:
* Host SVE being discarded unexpectedly due to inconsistent configuration of TIF_SVE and CPACR_ELx.ZEN. This has been seen to result in QEMU crashes where SVE is used by memmove(), as reported by Eric Auger:
https://issues.redhat.com/browse/RHEL-68997
* Host SVE state is discarded *after* modification by ptrace, which was an unintentional ptrace ABI change introduced with lazy discarding of SVE state.
* The host FPMR value can be discarded when running a non-protected VM, where FPMR support is not exposed to a VM, and that VM uses FPSIMD/SVE. In these cases the hyp code does not save the host's FPMR before unbinding the host's FPSIMD/SVE/SME state, leaving a stale value in memory.
Avoid these by eagerly saving and "flushing" the host's FPSIMD/SVE/SME state when loading a vCPU such that KVM does not need to save any of the host's FPSIMD/SVE/SME state. For clarity, fpsimd_kvm_prepare() is removed and the necessary call to fpsimd_save_and_flush_cpu_state() is placed in kvm_arch_vcpu_load_fp(). As 'fpsimd_state' and 'fpmr_ptr' should not be used, they are set to NULL; all uses of these will be removed in subsequent patches.
Historical problems go back at least as far as v5.17, e.g. erroneous assumptions about TIF_SVE being clear in commit:
8383741ab2e773a9 ("KVM: arm64: Get rid of host SVE tracking/saving")
... and so this eager save+flush probably needs to be backported to ALL stable trees.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.2
- Version 6.12.21StatusunaffectedConstraints<=6.12.*
- Version 6.13.9StatusunaffectedConstraints<=6.13.*
- Version 6.14StatusunaffectedConstraints<=*
- Version 6.6.85StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.2 · < 6.6.85
- ≥ 6.7 · < 6.12.21
- ≥ 6.13 · < 6.13.9
- 6.14
- 6.14
No data.
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.62.1.el9_4
Fixed · RHSA-2025:3510
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.62.1.el9_4 | Fixed | RHSA-2025:3510 |
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2025-22013 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2358222 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10342 Advisory
- https://git.kernel.org/stable/c/04c50cc23a492c4d43fdaefc7c1ecc0ff6f7b82e Patch
- https://git.kernel.org/stable/c/5289ac43b69c61a49c75720921f2008005a31c43 Patch
- https://git.kernel.org/stable/c/79e140bba70bcacc5fe15bf8c0b958793fd7d56f Patch
- https://git.kernel.org/stable/c/806d5c1e1d2e5502175a24bf70f251648d99c36a Patch
- https://git.kernel.org/stable/c/900b444be493b7f404898c785d6605b177a093d0 Patch
- https://git.kernel.org/stable/c/fbc7e61195e23f744814e78524b73b59faa54ab4 Patch
- https://lore.kernel.org/linux-cve-announce/2025040843-CVE-2025-22013-c885@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-22013
- https://www.cve.org/CVERecord?id=CVE-2025-22013
Change history (0)
No recorded changes yet.