3 ms·
Can you post a few links maybe to the SYSRET issue mentioned? Just curious.
by tfcata 9y ago
Can you post a few links maybe to the SYSRET issue mentioned? Just curious.
- amluto 9y agoSYSRET on Intel will fault with #GP if the kernel tries to go to a noncanonical user RIP. The #GP comes from kernel mode but with the user RSP. Before SMAP, this was an easy root if it happened. With SMAP, it's still pretty bad. AMD CPUs instead allow SYSRET to succeed and send #PF afterwards, which is very safe. AMD CPUs are differently dumb. If SYSRET is issued while SS=0, then the SS register ends up in a bogus state in which it appears to contain the correct value but 32-bit stack access fails. Search the Linux kernel for "SYSRET_SS_ATTRS" for the workaround.
- cesarb 9y agoI believe it's this one: https://blog.xenproject.org/2012/06/13/the-intel-sysret-privilege-escalation/ https://blog.xenproject.org/2012/06/13/the-intel-sysret-priv...