summary refs log tree commit diff stats
path: root/classification/semantic_issues/gitlab_semantic_bzhi
diff options
context:
space:
mode:
authorChristian Krinitsin <mail@krinitsin.com>2025-06-03 14:41:43 +0200
committerChristian Krinitsin <mail@krinitsin.com>2025-06-03 14:41:43 +0200
commitd760c82f4244dc47f5413c3c88b640bb1f0f2d9e (patch)
treeba963e9c548a5f19da2665005ce85946c601cd36 /classification/semantic_issues/gitlab_semantic_bzhi
parent256709d2eb3fd80d768a99964be5caa61effa2a0 (diff)
downloademulator-bug-study-d760c82f4244dc47f5413c3c88b640bb1f0f2d9e.tar.gz
emulator-bug-study-d760c82f4244dc47f5413c3c88b640bb1f0f2d9e.zip
move semantic_issues dir to results
Diffstat (limited to 'classification/semantic_issues/gitlab_semantic_bzhi')
-rw-r--r--classification/semantic_issues/gitlab_semantic_bzhi38
1 files changed, 0 insertions, 38 deletions
diff --git a/classification/semantic_issues/gitlab_semantic_bzhi b/classification/semantic_issues/gitlab_semantic_bzhi
deleted file mode 100644
index b86da08c..00000000
--- a/classification/semantic_issues/gitlab_semantic_bzhi
+++ /dev/null
@@ -1,38 +0,0 @@
-x86 BZHI semantic bug
-Description of problem
-The result of instruction BZHI is different from the CPU. The value of destination register and SF of EFLAGS are different.
-
-Steps to reproduce
-
-Compile this code
-
-
-void main() {
-    asm("mov rax, 0xb1aa9da2fe33fe3");
-    asm("mov rbx, 0x80000000ffffffff");
-    asm("mov rcx, 0xf3fce8829b99a5c6");
-    asm("bzhi rax, rbx, rcx");
-}
-
-
-
-Execute and compare the result with the CPU.
-
-CPU
-
-RAX = 0x0x80000000ffffffff
-SF = 1
-
-
-QEMU
-
-RAX = 0xffffffff
-SF = 0
-
-
-
-
-
-
-Additional information
-This bug is discovered by research conducted by KAIST SoftSec.