[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] [PATCH] x86/hvm: Fix use-after-free introduced by c/s 428607a


  • To: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Jan Beulich <JBeulich@xxxxxxxx>
  • From: Corneliu ZUZU <czuzu@xxxxxxxxxxxxxxx>
  • Date: Tue, 2 Feb 2016 14:51:11 +0200
  • Cc: Xen-devel <xen-devel@xxxxxxxxxxxxx>
  • Comment: DomainKeys? See http://domainkeys.sourceforge.net/
  • Delivery-date: Tue, 02 Feb 2016 12:51:25 +0000
  • Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=bitdefender.com; b=w1ruQf48HnWbJJbgkabHr6wmNP4nPstjY5jmIt8PxgCM17bZbdG4ZSq5H8Y0N9VMyawJms/Ke6VyE7+uqAgAHGGaYZOVnpQBO77RQml0rp4ZLIftZiF1F0gLKz+TB5WxXBzmHcA7mUpMs+4DQCNi+EjPpU6iZLigayvlJMSRSlhgAcwu46L1BJjPp/RiSPqK0El8Y8jHKxUeCtqndtXY95kKMMlAhJrrFC7iumjz9samPFIhl8eM1RVpRvGGLUbe38QSDQoRGxiYvDSxHCxX1ee9gO9CpmU3lKPsYoQsm8CiYuZQxJqq//nI11QEgiwEQsS3t43CM2xuVdwubbM0kw==; h=Received:Received:Received:Received:Received:Subject:To:References:Cc:From:Message-ID:Date:User-Agent:MIME-Version:In-Reply-To:Content-Type:Content-Transfer-Encoding:X-BitDefender-Scanner:X-BitDefender-Spam:X-BitDefender-SpamStamp:X-BitDefender-CF-Stamp;
  • List-id: Xen developer discussion <xen-devel.lists.xen.org>

On 2/2/2016 2:05 PM, Andrew Cooper wrote:
Xen and PV guests share the virtual address space, in exactly the same way as a native kernel and its userspace. PV guests can map pages at 0. Therefore, if Xen were to accidentally follow a NULL pointer, it may not result in a pagefault. (Hardware mechanisms such as SMEP and SMAP are added protection against this, but don't work on older hardware) ~Andrew

Thank you, I finally got it.
(I also read http://wiki.xenproject.org/wiki/X86_Paravirtualised_Memory_Management , cleared things up)

Corneliu.

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.