target/i386/tcg: validate segment registers
Correctly reject invalid segment registers, including CS when used as
the destination of a MOV. Ignore the REX prefix as well.
Fixes: 5e9e21bcc4 ("target/i386: move 60-BF opcodes to new decoder", 2024-05-07)
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3195
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
This commit is contained in:
parent
ebd9ea2947
commit
ebb46ba6a4
1 changed files with 6 additions and 1 deletions
|
|
@ -2059,7 +2059,12 @@ static bool decode_op(DisasContext *s, CPUX86State *env, X86DecodedInsn *decode,
|
|||
|
||||
case X86_TYPE_S: /* reg selects a segment register */
|
||||
op->unit = X86_OP_SEG;
|
||||
goto get_reg;
|
||||
op->n = (get_modrm(s, env) >> 3) & 7;
|
||||
/* Values outside [CDEFGS]S, as well as storing to CS, are invalid. */
|
||||
if (op->n >= 6 || (op->n == R_CS && op == &decode->op[0])) {
|
||||
return false;
|
||||
}
|
||||
break;
|
||||
|
||||
case X86_TYPE_P:
|
||||
op->unit = X86_OP_MMX;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue