summary refs log tree commit diff stats
path: root/results/classifier/user-mode-bugs/1832422
blob: ee67cf1041870b9367904cbdba8967b52304aaf9 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
SSE CMP ops with 8bit immediate throw sigill with oversized byte

The SSE comparison ops that use an 8bit immediate as a comparison type selector throws a sigill when the immediate is oversized.

Test op that I found this on is here `66 0f c2 c0 d1          cmppd  xmm0,xmm0,0xd1`
According to the x86-64 documentation only bits [2:0] are used for these ops (and [4:0] for the AVX variant)
Currently qemu just checks if the value is >=8 and will throw a sigill in that case. It instead needs to mask.

I have a small patch that fixes the issue for the SSE variant.