On 08.04.20 08:40, Sean Christopherson wrote: > Two fixes for what are effectively the same bug. The binary search used > for memslot lookup doesn't check the resolved index and can access memory > beyond the end of the memslot array. > > I split the s390 specific change to a separate patch because it's subtly > different, and to simplify backporting. The KVM wide fix can be applied > to stable trees as is, but AFAICT the s390 change would need to be paired > with the !used_slots check from commit 774a964ef56 ("KVM: Fix out of range I cannot find the commit id 774a964ef56