From: Ian Campbell Date: Tue, 12 Aug 2014 13:37:25 +0000 (+0200) Subject: xen: arm: Handle traps from 32-bit userspace on 64-bit kernel as undef X-Git-Tag: archive/raspbian/4.8.0-1+rpi1~1^2~4531 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=c0020e0997024eb741d60de9a480bf2878f891af;p=xen.git xen: arm: Handle traps from 32-bit userspace on 64-bit kernel as undef We are not setup to handle these properly. This turns a host crash into a trap to the guest kernel which will likely result in killing the offending process. This is part of CVE-2014-5147 / XSA-102. Signed-off-by: Ian Campbell Acked-by: Julien Grall --- diff --git a/xen/arch/arm/traps.c b/xen/arch/arm/traps.c index 7f34f1d786..ae594caea7 100644 --- a/xen/arch/arm/traps.c +++ b/xen/arch/arm/traps.c @@ -1841,6 +1841,17 @@ asmlinkage void do_trap_hypervisor(struct cpu_user_regs *regs) enter_hypervisor_head(regs); + /* + * We currently do not handle 32-bit userspace on 64-bit kernels + * correctly (See XSA-102). Until that is resolved we treat any + * trap from 32-bit userspace on 64-bit kernel as undefined. + */ + if ( is_64bit_domain(current->domain) && psr_mode_is_32bit(regs->cpsr) ) + { + inject_undef_exception(regs, hsr.len); + return; + } + switch (hsr.ec) { case HSR_EC_WFI_WFE: if ( !check_conditional_instr(regs, hsr) )