VirtualBox

Ticket #5248 (closed defect: fixed)

Opened 10 years ago

Last modified 10 years ago

Incorrect handling of 'Accessed' bit in page table entries -> fixed in SVN/3.0.10

Reported by: diamond Owned by:
Component: VMM/RAW Version: VirtualBox 3.0.8
Keywords: Cc:
Guest type: other Host type: other

Description

The function ModifyPage() from src/VBox/VMM/VMMAll/PGMAllGst.h assumes that size argument is page-aligned. However, PGMPhysInterpretedRead() from src/VBox/VMM/VMMAll/PGMAllPhys.cpp calls ModifyPage() with size=1. Due to the structure of ModifyPage(), this can cause setting 'Accessed' bit for entries of page table, which were not accessed, and in most serious cases this leads to the 'Guru Meditation' state.

Small examples for both cases is attached. Hardware virtualization must be disabled. Both examples are valid bootsectors and can be installed to virtual machine as floppy images; when booting from such floppy, in first case VirtualBox goes to 'Guru Meditation' VERR_TRPM_DONT_PANIC (VBox.log is attached, VBox.png contains black screen). The second example after access to page 0x8000 (through 'in al, dx' from ring-3, which loads allowed i/o ports bitmap, causing read from TSS) checks 'Accessed' bit of page 0x9000 and displays the letter 'M' at top-left corner of the screen.

Attachments

VBox.log Download (146.4 KB) - added by diamond 10 years ago.
1.bin Download (512 bytes) - added by diamond 10 years ago.
bootsector, which causes guru meditation
2.bin Download (512 bytes) - added by diamond 10 years ago.
bootsector, which displays unexpected modification

Change History

Changed 10 years ago by diamond

Changed 10 years ago by diamond

bootsector, which causes guru meditation

Changed 10 years ago by diamond

bootsector, which displays unexpected modification

comment:1 Changed 10 years ago by sandervl73

  • Summary changed from Incorrect handling of 'Accessed' bit in page table entries to Incorrect handling of 'Accessed' bit in page table entries -> fixed in SVN/3.0.10

Thanks for the detailed report! Fixed in SVN.

comment:2 Changed 10 years ago by frank

  • Status changed from new to closed
  • Resolution set to fixed
Note: See TracTickets for help on using tickets.

www.oracle.com
ContactPrivacy policyTerms of Use