From: Jan Beulich Date: Wed, 28 Nov 2018 14:50:26 +0000 (+0100) Subject: x86emul: correct 32-bit address handling for AVX2 gathers X-Git-Tag: archive/raspbian/4.14.0+80-gd101b417b7-1+rpi1^2~63^2~2817 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=298556c7b5f89243133378132a0c3024bdf6e563;p=xen.git x86emul: correct 32-bit address handling for AVX2 gathers As done for other cases by commit 7869e2bafe ("x86emul/fuzz: add rudimentary limit checking"), address calculations should also use truncate_ea() for the AVX2 gather insns. Signed-off-by: Jan Beulich Acked-by: Andrew Cooper --- diff --git a/xen/arch/x86/x86_emulate/x86_emulate.c b/xen/arch/x86/x86_emulate/x86_emulate.c index e11183d8d6..0ae433538e 100644 --- a/xen/arch/x86/x86_emulate/x86_emulate.c +++ b/xen/arch/x86/x86_emulate/x86_emulate.c @@ -8400,7 +8400,8 @@ x86_emulate( signed long idx = b & 1 ? index.qw[i] : index.dw[i]; rc = ops->read(ea.mem.seg, - ea.mem.off + (idx << state->sib_scale), + truncate_ea(ea.mem.off + + (idx << state->sib_scale)), (void *)mmvalp + i * op_bytes, op_bytes, ctxt); if ( rc != X86EMUL_OKAY ) {