From c0020e0997024eb741d60de9a480bf2878f891af Mon Sep 17 00:00:00 2001 From: Ian Campbell Date: Tue, 12 Aug 2014 15:37:25 +0200 Subject: [PATCH] xen: arm: Handle traps from 32-bit userspace on 64-bit kernel as undef We are not setup to handle these properly. This turns a host crash into a trap to the guest kernel which will likely result in killing the offending process. This is part of CVE-2014-5147 / XSA-102. Signed-off-by: Ian Campbell Acked-by: Julien Grall --- xen/arch/arm/traps.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/xen/arch/arm/traps.c b/xen/arch/arm/traps.c index 7f34f1d786..ae594caea7 100644 --- a/xen/arch/arm/traps.c +++ b/xen/arch/arm/traps.c @@ -1841,6 +1841,17 @@ asmlinkage void do_trap_hypervisor(struct cpu_user_regs *regs) enter_hypervisor_head(regs); + /* + * We currently do not handle 32-bit userspace on 64-bit kernels + * correctly (See XSA-102). Until that is resolved we treat any + * trap from 32-bit userspace on 64-bit kernel as undefined. + */ + if ( is_64bit_domain(current->domain) && psr_mode_is_32bit(regs->cpsr) ) + { + inject_undef_exception(regs, hsr.len); + return; + } + switch (hsr.ec) { case HSR_EC_WFI_WFE: if ( !check_conditional_instr(regs, hsr) ) -- 2.30.2