]> git.kernelconcepts.de Git - karo-tx-linux.git/commit
KVM: x86: SYSENTER emulation is broken
authorNadav Amit <namit@cs.technion.ac.il>
Thu, 1 Jan 2015 21:11:11 +0000 (23:11 +0200)
committerPaolo Bonzini <pbonzini@redhat.com>
Fri, 23 Jan 2015 12:57:15 +0000 (13:57 +0100)
commitf3747379accba8e95d70cec0eae0582c8c182050
tree4ec2d6f001a3eb058905a9d258c78f43b41f13a1
parent63ea0a49ae0b145b91ff2b070c01b66fc75854b9
KVM: x86: SYSENTER emulation is broken

SYSENTER emulation is broken in several ways:
1. It misses the case of 16-bit code segments completely (CVE-2015-0239).
2. MSR_IA32_SYSENTER_CS is checked in 64-bit mode incorrectly (bits 0 and 1 can
   still be set without causing #GP).
3. MSR_IA32_SYSENTER_EIP and MSR_IA32_SYSENTER_ESP are not masked in
   legacy-mode.
4. There is some unneeded code.

Fix it.

Cc: stable@vger.linux.org
Signed-off-by: Nadav Amit <namit@cs.technion.ac.il>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
arch/x86/kvm/emulate.c