From: Jan Beulich Date: Wed, 23 Nov 2016 14:26:11 +0000 (+0100) Subject: x86/HVM: limit writes to outgoing TSS during task switch X-Git-Tag: archive/raspbian/4.8.0-1+rpi1~1^2~76 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=bac3e8e0f50aaf01eaf064b5201f69759fa87803;p=xen.git x86/HVM: limit writes to outgoing TSS during task switch The only fields modified are EIP, EFLAGS, GPRs, and segment selectors. CR3 in particular is not supposed to be updated. Signed-off-by: Jan Beulich Reviewed-by: Andrew Cooper Release-acked-by: Wei Liu --- diff --git a/xen/arch/x86/hvm/hvm.c b/xen/arch/x86/hvm/hvm.c index bde7640b1d..74d8909425 100644 --- a/xen/arch/x86/hvm/hvm.c +++ b/xen/arch/x86/hvm/hvm.c @@ -2952,7 +2952,6 @@ void hvm_task_switch( if ( taskswitch_reason == TSW_iret ) eflags &= ~X86_EFLAGS_NT; - tss.cr3 = v->arch.hvm_vcpu.guest_cr[3]; tss.eip = regs->eip; tss.eflags = eflags; tss.eax = regs->eax; @@ -2979,8 +2978,11 @@ void hvm_task_switch( hvm_get_segment_register(v, x86_seg_ldtr, &segr); tss.ldt = segr.sel; - rc = hvm_copy_to_guest_virt( - prev_tr.base, &tss, sizeof(tss), PFEC_page_present); + rc = hvm_copy_to_guest_virt(prev_tr.base + offsetof(typeof(tss), eip), + &tss.eip, + offsetof(typeof(tss), trace) - + offsetof(typeof(tss), eip), + PFEC_page_present); if ( rc != HVMCOPY_okay ) goto out;