Re: [PATCH] target/i386: Add missing CPL==0 check when returning to VM86

Hrvoje Mišetić <[email protected]>
Newsgroups gmane.comp.emulators.qemu
Message-ID <CAFF5j3+AMxyXeU2+JGga7ve_mpdK8hYKO1OjuKx-ytNLmgG_Ww@mail.gmail.com>
Bumping this:
https://lore.kernel.org/qemu-devel/[email protected]/T/#u

Any comments or suggestions on the patch?

Thanks,
Hrvoje

On Thu, May 28, 2026 at 1:38 PM Hrvoje Misetic <[email protected]> wrote:

> helper_ret_protected only checks if the VM flag is set in the new eflags,
> while the Intel manual says:
> IF tempEFLAGS(VM) = 1 and CPL = 0
>         THEN GOTO RETURN-TO-VIRTUAL-8086-MODE;
>
> As CPL==0 check is missing in QEMU TCG, a 32-bit binary inside the guest
> can elevate privileges by executing an iret and returning to VM86 while
> setting IOPL to 3.
>
> Fixes: 90a9fdae1f1a ("more ring 0 operations")
> Signed-off-by: Hrvoje Misetic <[email protected]>
> ---
>  target/i386/tcg/seg_helper.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/target/i386/tcg/seg_helper.c b/target/i386/tcg/seg_helper.c
> index 58aac72011..57cf668131 100644
> --- a/target/i386/tcg/seg_helper.c
> +++ b/target/i386/tcg/seg_helper.c
> @@ -2068,7 +2068,7 @@ static inline void helper_ret_protected(CPUX86State
> *env, int shift,
>              new_cs = popl(&sa) & 0xffff;
>              if (is_iret) {
>                  new_eflags = popl(&sa);
> -                if (new_eflags & VM_MASK) {
> +                if (new_eflags & VM_MASK && cpl == 0) {
>                      goto return_to_vm86;
>                  }
>              }
> --
> 2.48.1
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.