kvm: x86: Check memopp before dereference (CVE-2016-8630)
commit d9092f52d7e61dd1557f2db2400ddb430e85937e upstream. Commit41061cdb98
("KVM: emulate: do not initialize memopp") removes a check for non-NULL under incorrect assumptions. An undefined instruction with a ModR/M byte with Mod=0 and R/M-5 (e.g. 0xc7 0x15) will attempt to dereference a null pointer here. Fixes:41061cdb98
Message-Id: <1477592752-126650-2-git-send-email-osh@google.com> Signed-off-by: Owen Hofmann <osh@google.com> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
62fa839b8f
commit
91e1f7b0eb
1 changed files with 1 additions and 1 deletions
|
@ -5033,7 +5033,7 @@ done_prefixes:
|
||||||
/* Decode and fetch the destination operand: register or memory. */
|
/* Decode and fetch the destination operand: register or memory. */
|
||||||
rc = decode_operand(ctxt, &ctxt->dst, (ctxt->d >> DstShift) & OpMask);
|
rc = decode_operand(ctxt, &ctxt->dst, (ctxt->d >> DstShift) & OpMask);
|
||||||
|
|
||||||
if (ctxt->rip_relative)
|
if (ctxt->rip_relative && likely(ctxt->memopp))
|
||||||
ctxt->memopp->addr.mem.ea = address_mask(ctxt,
|
ctxt->memopp->addr.mem.ea = address_mask(ctxt,
|
||||||
ctxt->memopp->addr.mem.ea + ctxt->_eip);
|
ctxt->memopp->addr.mem.ea + ctxt->_eip);
|
||||||
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue