Commit 12c1f6e03f94 for kernel

commit 12c1f6e03f944e399bd2c88441dca5dc702b95a5
Author: Sean Christopherson <seanjc@google.com>
Date:   Wed Sep 23 09:37:20 2026 -0700

    KVM: SEV: Free have_run_cpus during VM destruction even if VM is no longer SEV

    Unconditionally free SEV's "have run CPUs" cpumask in the VM destroy path,
    i.e. even for what appear to be non-SEV VMs, as an SEV VM becomes a non-SEV
    VM if its state is intra-host migrated.  Alternatively, the mask could be
    freed in sev_migrate_from() when "converting" the source VM, but that gets
    annoying because ideally KVM would nullify the mask to guard against UAF,
    and nullifying the mask would need be conditioned on CPUMASK_OFFSTACK=y.

    Freeing the mask during sev_migrate_from() is also not robust against other
    KVM bugs, though that's kind of a moot point since any such bugs would show
    up even if sev->active is never set.  I.e. KVM must get that side of things
    correct.  But, that's not a great reason to add more code just to make
    things marginally less robust.

    Fixes: 6f38f8c57464 ("KVM: SVM: Flush cache only on CPUs running SEV guest")
    Cc: stable@vger.kernel.org
    Reported-by: Stefan Teodorescu <fane@google.com>
    Signed-off-by: Sean Christopherson <seanjc@google.com>
    Message-ID: <20260923163721.1584779-2-seanjc@google.com>
    Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c
index 5705723f1f41..cdc1c04f60da 100644
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -2980,13 +2980,17 @@ void sev_vm_destroy(struct kvm *kvm)
 	struct list_head *head = &sev->regions_list;
 	struct list_head *pos, *q;

+	/*
+	 * Free the mask even if the VM is not *currently* an SEV VM, as it may
+	 * have been an SEV VM prior to intra-host migration.
+	 */
+	free_cpumask_var(sev->have_run_cpus);
+
 	if (!sev_guest(kvm))
 		return;

 	WARN_ON(!list_empty(&sev->mirror_vms));

-	free_cpumask_var(sev->have_run_cpus);
-
 	/*
 	 * If this is a mirror VM, remove it from the owner's list of a mirrors
 	 * and skip ASID cleanup (the ASID is tied to the lifetime of the owner).