diff options
author | Jan Beulich <jbeulich@suse.com> | 2013-09-30 14:29:38 +0200 |
---|---|---|
committer | Jan Beulich <jbeulich@suse.com> | 2013-09-30 14:29:38 +0200 |
commit | 09962956f799de2a0f5d6589d52ed7755eaf6ac3 (patch) | |
tree | 53f703accc119957bfb236651d1ed41e16319b6e | |
parent | 62f395f6ae43a0f2c3d48db4ca2b2535cb6f490f (diff) | |
download | xen-09962956f799de2a0f5d6589d52ed7755eaf6ac3.tar.gz xen-09962956f799de2a0f5d6589d52ed7755eaf6ac3.tar.bz2 xen-09962956f799de2a0f5d6589d52ed7755eaf6ac3.zip |
x86: properly set up fbld emulation operand address
This is CVE-2013-4361 / XSA-66.
Signed-off-by: Jan Beulich <jbeulich@suse.com>
Acked-by: Ian Jackson <ian.jackson@eu.citrix.com>
master commit: 28b706efb6abb637fabfd74cde70a50935a5640b
master date: 2013-09-30 14:18:58 +0200
-rw-r--r-- | xen/arch/x86/x86_emulate/x86_emulate.c | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/xen/arch/x86/x86_emulate/x86_emulate.c b/xen/arch/x86/x86_emulate/x86_emulate.c index 1bac6b8e2b..deefdb9072 100644 --- a/xen/arch/x86/x86_emulate/x86_emulate.c +++ b/xen/arch/x86/x86_emulate/x86_emulate.c @@ -3159,11 +3159,11 @@ x86_emulate( break; case 4: /* fbld m80dec */ ea.bytes = 10; - dst = ea; + src = ea; if ( (rc = ops->read(src.mem.seg, src.mem.off, &src.val, src.bytes, ctxt)) != 0 ) goto done; - emulate_fpu_insn_memdst("fbld", src.val); + emulate_fpu_insn_memsrc("fbld", src.val); break; case 5: /* fild m64i */ ea.bytes = 8; |