summary refs log tree commit diff stats
path: root/results/classifier/semantic-bugs/semantic/1374
diff options
context:
space:
mode:
authorChristian Krinitsin <mail@krinitsin.com>2025-06-12 09:56:59 +0200
committerChristian Krinitsin <mail@krinitsin.com>2025-06-12 09:56:59 +0200
commitb89a938452613061c0f1f23e710281cf5c83cb29 (patch)
treed5faecfd167e088848cad894f8dc9cfef3352e3b /results/classifier/semantic-bugs/semantic/1374
parent7b681b9f9eedaad2f081ae11a32f459f5a1312ff (diff)
downloademulator-bug-study-b89a938452613061c0f1f23e710281cf5c83cb29.tar.gz
emulator-bug-study-b89a938452613061c0f1f23e710281cf5c83cb29.zip
add manually reviewed semantic bugs
Diffstat (limited to 'results/classifier/semantic-bugs/semantic/1374')
-rw-r--r--results/classifier/semantic-bugs/semantic/137435
1 files changed, 35 insertions, 0 deletions
diff --git a/results/classifier/semantic-bugs/semantic/1374 b/results/classifier/semantic-bugs/semantic/1374
new file mode 100644
index 00000000..0db6a019
--- /dev/null
+++ b/results/classifier/semantic-bugs/semantic/1374
@@ -0,0 +1,35 @@
+semantic: 0.993
+instruction: 0.952
+graphic: 0.807
+device: 0.700
+assembly: 0.661
+boot: 0.382
+vnc: 0.341
+socket: 0.314
+network: 0.272
+mistranslation: 0.272
+other: 0.093
+KVM: 0.044
+
+x86 BZHI semantic bug
+Description of problem:
+The result of instruction BZHI is different from the CPU. The value of destination register and SF of EFLAGS are different.
+Steps to reproduce:
+1. Compile this code
+```
+void main() {
+    asm("mov rax, 0xb1aa9da2fe33fe3");
+    asm("mov rbx, 0x80000000ffffffff");
+    asm("mov rcx, 0xf3fce8829b99a5c6");
+    asm("bzhi rax, rbx, rcx");
+}
+```
+2. Execute and compare the result with the CPU.
+    - CPU
+        - RAX = 0x0x80000000ffffffff
+        - SF = 1
+    - QEMU
+        - RAX = 0xffffffff
+        - SF = 0
+Additional information:
+This bug is discovered by research conducted by KAIST SoftSec.