android_kernel_motorola_sm6375/arch
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Sean Christopherson ad5c71fa9b x86/umip: Check that the instruction opcode is at least two bytes
commit 32278c677947ae2f042c9535674a7fff9a245dd3 upstream.

When checking for a potential UMIP violation on #GP, verify the decoder found
at least two opcode bytes to avoid false positives when the kernel encounters
an unknown instruction that starts with 0f.  Because the array of opcode.bytes
is zero-initialized by insn_init(), peeking at bytes[1] will misinterpret
garbage as a potential SLDT or STR instruction, and can incorrectly trigger
emulation.

E.g. if a VPALIGNR instruction

   62 83 c5 05 0f 08 ff     vpalignr xmm17{k5},xmm23,XMMWORD PTR [r8],0xff

hits a #GP, the kernel emulates it as STR and squashes the #GP (and corrupts
the userspace code stream).

Arguably the check should look for exactly two bytes, but no three byte
opcodes use '0f 00 xx' or '0f 01 xx' as an escape, i.e. it should be
impossible to get a false positive if the first two opcode bytes match '0f 00'
or '0f 01'.  Go with a more conservative check with respect to the existing
code to minimize the chances of breaking userspace, e.g. due to decoder
weirdness.

Analyzed by Nick Bray <ncbray@google.com>.

Fixes: 1e5db22369 ("x86/umip: Add emulation code for UMIP instructions")
Reported-by: Dan Snyder <dansnyder@google.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:54 +01:00
..
alpha
arc
arm ARM: 9448/1: Use an absolute path to unified.h in KBUILD_AFLAGS 2025-08-28 16:21:32 +02:00
arm64 arm64: dts: qcom: msm8916: Add missing MDSS reset 2025-10-29 13:59:52 +01:00
c6x
csky
h8300
hexagon
ia64
m68k m68k: Fix lost column on framebuffer debug console 2025-08-28 16:21:30 +02:00
microblaze
mips mips: Include KBUILD_CPPFLAGS in CHECKFLAGS invocation 2025-08-28 16:21:33 +02:00
nds32
nios2 nios2: force update_mmu_cache on spurious tlb-permission--related pagefaults 2025-06-27 11:02:54 +01:00
openrisc
parisc parisc: don't reference obsolete termio struct for TC* constants 2025-10-29 13:59:53 +01:00
powerpc powerpc: boot: Remove leading zero in label in udelay() 2025-09-09 18:43:56 +02:00
riscv riscv: Avoid fortify warning in syscall_get_arguments() 2025-05-02 07:39:20 +02:00
s390 s390/hypfs: Enable limited access during lockdown 2025-08-28 16:21:37 +02:00
sh
sparc sparc: fix error handling in scan_one_device() 2025-10-29 13:59:53 +01:00
um um: ubd: Add missing error check in start_io_thread() 2025-07-17 18:24:53 +02:00
unicore32
x86 x86/umip: Check that the instruction opcode is at least two bytes 2025-10-29 13:59:54 +01:00
xtensa
.gitignore
Kconfig