diff options
author | Sona Sarmadi <sona.sarmadi@enea.com> | 2017-05-16 13:05:37 +0200 |
---|---|---|
committer | Adrian Dudau <adrian.dudau@enea.com> | 2017-05-19 14:32:39 +0200 |
commit | bf0c5869f5f9a77d6c7c1adfb7c802d5bb0a1a74 (patch) | |
tree | b2d65d194cb2c5a3bf2b14a74c7d8f8f5fc9ad70 /meta/recipes-devtools/qemu/qemu/target-ppc-fix-user-mode.patch | |
parent | cb2cf64b0b33e70b8f017b8757f8d4dd0ba10431 (diff) | |
download | poky-bf0c5869f5f9a77d6c7c1adfb7c802d5bb0a1a74.tar.gz |
Qemu: update to 2.8.1.1
Fixed CVE:
- CVE-2017-2620 (Severity = High)
display: cirrus: potential arbitrary code execution via cirrus_bitblt_cputovideo
Removed patches (already in upstream):
- target-ppc-fix-user-mode.patch (already in upstream)
Clean up:
- CVE-2016-2198.patch (this patch is removed from recipes but the patch was not deleted)
Signed-off-by: Sona Sarmadi <sona.sarmadi@enea.com>
Signed-off-by: Adrian Dudau <adrian.dudau@enea.com>
Diffstat (limited to 'meta/recipes-devtools/qemu/qemu/target-ppc-fix-user-mode.patch')
-rw-r--r-- | meta/recipes-devtools/qemu/qemu/target-ppc-fix-user-mode.patch | 48 |
1 files changed, 0 insertions, 48 deletions
diff --git a/meta/recipes-devtools/qemu/qemu/target-ppc-fix-user-mode.patch b/meta/recipes-devtools/qemu/qemu/target-ppc-fix-user-mode.patch deleted file mode 100644 index ba21e71b0f..0000000000 --- a/meta/recipes-devtools/qemu/qemu/target-ppc-fix-user-mode.patch +++ /dev/null | |||
@@ -1,48 +0,0 @@ | |||
1 | [Qemu-ppc] [PATCH 1/1] target-ppc, tcg: fix usermode segfault with pthread | ||
2 | |||
3 | From: Sam Bobroff | ||
4 | Subject: [Qemu-ppc] [PATCH 1/1] target-ppc, tcg: fix usermode segfault with pthread_create() | ||
5 | Date: Mon, 30 Jan 2017 16:08:07 +1100 | ||
6 | Programs run under qemu-ppc64 on an x86_64 host currently segfault | ||
7 | if they use pthread_create() due to the adjustment made to the NIP in | ||
8 | commit bd6fefe71cec5a0c7d2be4ac96307f25db56abf9. | ||
9 | |||
10 | This patch changes cpu_loop() to set the NIP back to the | ||
11 | pre-incremented value before calling do_syscall(), which causes the | ||
12 | correct address to be used for the new thread and corrects the fault. | ||
13 | |||
14 | Signed-off-by: Sam Bobroff <address@hidden> | ||
15 | |||
16 | Upstream-Status: Backport | ||
17 | |||
18 | --- | ||
19 | |||
20 | linux-user/main.c | 4 +++- | ||
21 | 1 file changed, 3 insertions(+), 1 deletion(-) | ||
22 | |||
23 | diff --git a/linux-user/main.c b/linux-user/main.c | ||
24 | index 30049581ef..b5dee01541 100644 | ||
25 | --- a/linux-user/main.c | ||
26 | +++ b/linux-user/main.c | ||
27 | @@ -1712,18 +1712,20 @@ void cpu_loop(CPUPPCState *env) | ||
28 | * in syscalls. | ||
29 | */ | ||
30 | env->crf[0] &= ~0x1; | ||
31 | + env->nip += 4; | ||
32 | ret = do_syscall(env, env->gpr[0], env->gpr[3], env->gpr[4], | ||
33 | env->gpr[5], env->gpr[6], env->gpr[7], | ||
34 | env->gpr[8], 0, 0); | ||
35 | if (ret == -TARGET_ERESTARTSYS) { | ||
36 | + env->nip -= 4; | ||
37 | break; | ||
38 | } | ||
39 | if (ret == (target_ulong)(-TARGET_QEMU_ESIGRETURN)) { | ||
40 | + env->nip -= 4; | ||
41 | /* Returning from a successful sigreturn syscall. | ||
42 | Avoid corrupting register state. */ | ||
43 | break; | ||
44 | } | ||
45 | - env->nip += 4; | ||
46 | if (ret > (target_ulong)(-515)) { | ||
47 | env->crf[0] |= 0x1; | ||
48 | ret = -ret; | ||