diff options
| author | Christian Krinitsin <mail@krinitsin.com> | 2025-06-03 14:41:43 +0200 |
|---|---|---|
| committer | Christian Krinitsin <mail@krinitsin.com> | 2025-06-03 14:41:43 +0200 |
| commit | d760c82f4244dc47f5413c3c88b640bb1f0f2d9e (patch) | |
| tree | ba963e9c548a5f19da2665005ce85946c601cd36 /classification/semantic_issues/gitlab_semantic_bzhi | |
| parent | 256709d2eb3fd80d768a99964be5caa61effa2a0 (diff) | |
| download | emulator-bug-study-d760c82f4244dc47f5413c3c88b640bb1f0f2d9e.tar.gz emulator-bug-study-d760c82f4244dc47f5413c3c88b640bb1f0f2d9e.zip | |
move semantic_issues dir to results
Diffstat (limited to 'classification/semantic_issues/gitlab_semantic_bzhi')
| -rw-r--r-- | classification/semantic_issues/gitlab_semantic_bzhi | 38 |
1 files changed, 0 insertions, 38 deletions
diff --git a/classification/semantic_issues/gitlab_semantic_bzhi b/classification/semantic_issues/gitlab_semantic_bzhi deleted file mode 100644 index b86da08c..00000000 --- a/classification/semantic_issues/gitlab_semantic_bzhi +++ /dev/null @@ -1,38 +0,0 @@ -x86 BZHI semantic bug -Description of problem -The result of instruction BZHI is different from the CPU. The value of destination register and SF of EFLAGS are different. - -Steps to reproduce - -Compile this code - - -void main() { - asm("mov rax, 0xb1aa9da2fe33fe3"); - asm("mov rbx, 0x80000000ffffffff"); - asm("mov rcx, 0xf3fce8829b99a5c6"); - asm("bzhi rax, rbx, rcx"); -} - - - -Execute and compare the result with the CPU. - -CPU - -RAX = 0x0x80000000ffffffff -SF = 1 - - -QEMU - -RAX = 0xffffffff -SF = 0 - - - - - - -Additional information -This bug is discovered by research conducted by KAIST SoftSec. |