summary refs log tree commit diff stats
path: root/results/classifier/zero-shot/016/assembly-x86/gitlab_semantic_adox
blob: 172b6260cf6237837ed758e79b2bddd2c90714e8 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
x86: 1.000
assembly: 0.986
semantic: 0.984
i386: 0.965
debug: 0.322
register: 0.126
operating system: 0.048
files: 0.023
TCG: 0.018
kernel: 0.015
performance: 0.015
virtual: 0.013
user-level: 0.009
architecture: 0.007
PID: 0.007
device: 0.005
peripherals: 0.005
hypervisor: 0.004
VMM: 0.004
KVM: 0.003
network: 0.002
boot: 0.002
graphic: 0.002
permissions: 0.002
socket: 0.002
alpha: 0.002
risc-v: 0.002
ppc: 0.001
vnc: 0.001
mistranslation: 0.000
arm: 0.000

x86 ADOX and ADCX semantic bug
Description of problem
The result of instruction ADOX and ADCX are different from the CPU. The value of one of EFLAGS is different.

Steps to reproduce

Compile this code


void main() {
    asm("push 512; popfq;");
    asm("mov rax, 0xffffffff84fdbf24");
    asm("mov rbx, 0xb197d26043bec15d");
    asm("adox eax, ebx");
}



Execute and compare the result with the CPU. This problem happens with ADCX, too (with CF).

CPU

OF = 0


QEMU

OF = 1






Additional information
This bug is discovered by research conducted by KAIST SoftSec.