summary refs log tree commit diff stats
path: root/results/classifier/semantic-bugs/1374
diff options
context:
space:
mode:
authorChristian Krinitsin <mail@krinitsin.com>2025-07-03 19:39:53 +0200
committerChristian Krinitsin <mail@krinitsin.com>2025-07-03 19:39:53 +0200
commitdee4dcba78baf712cab403d47d9db319ab7f95d6 (patch)
tree418478faf06786701a56268672f73d6b0b4eb239 /results/classifier/semantic-bugs/1374
parent4d9e26c0333abd39bdbd039dcdb30ed429c475ba (diff)
downloadqemu-analysis-dee4dcba78baf712cab403d47d9db319ab7f95d6.tar.gz
qemu-analysis-dee4dcba78baf712cab403d47d9db319ab7f95d6.zip
restructure results
Diffstat (limited to 'results/classifier/semantic-bugs/1374')
-rw-r--r--results/classifier/semantic-bugs/137435
1 files changed, 35 insertions, 0 deletions
diff --git a/results/classifier/semantic-bugs/1374 b/results/classifier/semantic-bugs/1374
new file mode 100644
index 000000000..0db6a0198
--- /dev/null
+++ b/results/classifier/semantic-bugs/1374
@@ -0,0 +1,35 @@
+semantic: 0.993
+instruction: 0.952
+graphic: 0.807
+device: 0.700
+assembly: 0.661
+boot: 0.382
+vnc: 0.341
+socket: 0.314
+network: 0.272
+mistranslation: 0.272
+other: 0.093
+KVM: 0.044
+
+x86 BZHI semantic bug
+Description of problem:
+The result of instruction BZHI is different from the CPU. The value of destination register and SF of EFLAGS are different.
+Steps to reproduce:
+1. Compile this code
+```
+void main() {
+    asm("mov rax, 0xb1aa9da2fe33fe3");
+    asm("mov rbx, 0x80000000ffffffff");
+    asm("mov rcx, 0xf3fce8829b99a5c6");
+    asm("bzhi rax, rbx, rcx");
+}
+```
+2. Execute and compare the result with the CPU.
+    - CPU
+        - RAX = 0x0x80000000ffffffff
+        - SF = 1
+    - QEMU
+        - RAX = 0xffffffff
+        - SF = 0
+Additional information:
+This bug is discovered by research conducted by KAIST SoftSec.