diff options
author | Nadav Amit <namit@cs.technion.ac.il> | 2015-01-01 23:11:11 +0200 |
---|---|---|
committer | Paolo Bonzini <pbonzini@redhat.com> | 2015-01-23 13:57:15 +0100 |
commit | f3747379accba8e95d70cec0eae0582c8c182050 (patch) | |
tree | 4ec2d6f001a3eb058905a9d258c78f43b41f13a1 /include | |
parent | 63ea0a49ae0b145b91ff2b070c01b66fc75854b9 (diff) | |
download | linux-f3747379accba8e95d70cec0eae0582c8c182050.tar.gz linux-f3747379accba8e95d70cec0eae0582c8c182050.tar.bz2 linux-f3747379accba8e95d70cec0eae0582c8c182050.zip |
KVM: x86: SYSENTER emulation is broken
SYSENTER emulation is broken in several ways:
1. It misses the case of 16-bit code segments completely (CVE-2015-0239).
2. MSR_IA32_SYSENTER_CS is checked in 64-bit mode incorrectly (bits 0 and 1 can
still be set without causing #GP).
3. MSR_IA32_SYSENTER_EIP and MSR_IA32_SYSENTER_ESP are not masked in
legacy-mode.
4. There is some unneeded code.
Fix it.
Cc: stable@vger.linux.org
Signed-off-by: Nadav Amit <namit@cs.technion.ac.il>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions