On 9/13/24 10:05, Alexey Gladkov wrote: > TDX only supports kernel-initiated MMIO operations. The handle_mmio() > function checks if the #VE exception occurred in the kernel and rejects > the operation if it did not. > > However, userspace can deceive the kernel into performing MMIO on its > behalf. For example, if userspace can point a syscall to an MMIO address, > syscall does get_user() or put_user() on it, triggering MMIO #VE. The > kernel will treat the #VE as in-kernel MMIO. > > Ensure that the target MMIO address is within the kernel before decoding > instruction. Acked-by: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>