TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

QEMU: user-to-root privesc inside VM via bad translation caching

99 点作者 webaholic大约 8 年前

3 条评论

tyingq大约 8 年前
<i>&quot;However, while real X86 processors have a maximum instruction length of 15 bytes, QEMU&#x27;s instruction decoder for X86 does not place any limit on the instruction and length or the number of instruction prefixes.&quot;</i><p>Interesting, and not your usual type of exploit. Guessing this isn&#x27;t one that will have the Rust crowd doling out &quot;told ya so&quot; :). Logic error only. No buffer overflow, not much strong types do for you, etc.
评论 #13928970 未加载
评论 #13929463 未加载
评论 #13929311 未加载
评论 #13930631 未加载
评论 #13929122 未加载
omribahumi大约 8 年前
&gt; To be clear: As far as I know, this bug only affects the TCG mode (without hardware acceleration), not KVM VMs or so.<p>I wonder what&#x27;s the reach of that bug.
评论 #13929216 未加载
评论 #13928756 未加载
gbrown_大约 8 年前
Not sure why this wasn&#x27;t duped to <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13921305" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13921305</a>
评论 #13929544 未加载