[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[BUG] x86emul/test: avoid assertion in emul_test_read_xcr() when XSAVE is absent



While running the x86_instruction_emulator fuzzer via AFL, I encountered an 
assertion failure in the emul_test_read_xcr() function.
The fuzzer is able to generate a CPU state where cpu_has_xsave is false. If the 
fuzzer then generates & feeds an instruction containing AVX,the emulator
attempts to fetch the FPU state via x86emul_get_fpu(), which then calls 
emul_test_read_xcr() and hits the ASSERT(cpu_has_xsave). This assertion crashes 
the fuzzer.

The crash:
1. $ ./afl-harness < findings_dir/master01/...
   afl-harness: ../../tests/x86_emulator/x86-emulate.c:179: emul_test_read_xcr: 
Assertion `cpu_has_xsave' failed.
   Aborted

2. The stacktrace:
(gdb) bt
data_p=data_p@entry=0x55555604f320 <input> 
"\244\264\336\346\337\001\254%\247R\216d\204*\234\377\377\224λ\3237/\365ʿX\266?\353\036\227/\0323\351dj\257\v\207\031V֖\235{\036\225|:M\330\336
 
\314V:&\357\306@\224\331,\301\300\372FW\262.\020\\\276\244\203\242\276\262\022!\337)F&\261\2064\200\200\377I;J\376X41\2061\206\325
 \021\017F\026\267\275\340\361\357)\255\343\237n\377\374n\357#ֽ\226\365d",
size=size@entry=580) at fuzz-emul.c:934

Possible fixes:
To prevent the fuzzer from getting stuck on this state,would it be better for 
emul_test_read_xcr to return X86EMUL_UNHANDLEABLE (or something similar) 
instead of ASSERT(cpu_has_xsave) ?

I have attached the binary crash file(converted to Base64) found by AFL below:

pLTe5t8BrCWnUo5khCqc//+UzrvTNy/1yr9Ytj/rHpcvGjPpZGqvC4cZVtaWnXselXw6TdjeIMxW
OibvxkCU2SzBwPpGV7IuEFy+pIOivrISId8pRiaxhjSAgP9JO0r+WDQxhjGG1SARD0YWt73g8e8p
reOfbv/8bu8j1r2W9WQAJnNNzsTXiDzn+tIYXP5ib7u5oA9GFre94PHvKa3jn27N/G7vI9a9lvVk
f/9fO1wsISMXjMG1qMtVHNLp6uRBZb1cV0Ybc1T5SBvfAawlp1KOZIQqnP//lOi70zgv9cq/WPWk
5MOmSoAqmv+M1R9Sc8UnJgEA9fX1IvX19fXu9fX19fX19fX19fX1/+dKZ6S03ubfAawlv1j1pOTD
pkqAKpr/jDcv9cq/WLY/6x6XLxoz6WRrrguGGVbWlsD6RleQLuUQkKSDoqayEiHf1kYmsYY0gFPE
gP9JO0r+VzQxhtUgEdeIPOf60hhcBmJvu7mgD0YWt73g8e8preOfbv/8bu/c1sbQS2L9zkVE9Ohz
xScmAQD19fUi9fVfO1xJAAACAMG1qMtVHNLp6uRBZX+AAAAbc1TaSBsdNdgkffrwwtCPjXe/D62n
Z+mGpLTe5t8BrCWnUo5khCqc//+UzrvTNy/1yr9Ytj/rHpcvGjPpZGuuC4cZVtaWnXselXw6TQAP
f/9WOibvxpCU2SzBwPpGV7IuEFy+pIOivrISId8pRiaxhjSAZWVlZWVlZWVlZWVlZWVlZWJlZWVl
ZWVleGVlZWVlZQ==

Signed-off-by: Andrew Mbugua <andrewprecious388@xxxxxxxxx>
---
 tools/tests/x86_emulator/x86-emulate.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/tools/tests/x86_emulator/x86-emulate.c 
b/tools/tests/x86_emulator/x86-emulate.c
index e2fbeb52e7..4d0b4610b5 100644
--- a/tools/tests/x86_emulator/x86-emulate.c
+++ b/tools/tests/x86_emulator/x86-emulate.c
@@ -176,7 +176,8 @@ int emul_test_read_xcr(
 {
     uint32_t lo, hi;
 
-    ASSERT(cpu_has_xsave);
+    if ( !cpu_has_xsave )
+       return X86EMUL_UNHANDLEABLE;
 
     switch ( reg )
     {
-- 
2.47.3




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.