VirtualBox

Ticket #5248 (closed defect: fixed)

Opened 5 years ago

Last modified 4 years ago

Incorrect handling of 'Accessed' bit in page table entries -> fixed in SVN/3.0.10

Reported by: diamond Owned by:
Priority: major Component: VMM/RAW
Version: VirtualBox 3.0.8 Keywords:
Cc: Guest type: other
Host type: other

Description

The function ModifyPage() from src/VBox/VMM/VMMAll/PGMAllGst.h assumes that size argument is page-aligned. However, PGMPhysInterpretedRead() from src/VBox/VMM/VMMAll/PGMAllPhys.cpp calls ModifyPage() with size=1. Due to the structure of ModifyPage(), this can cause setting 'Accessed' bit for entries of page table, which were not accessed, and in most serious cases this leads to the 'Guru Meditation' state.

Small examples for both cases is attached. Hardware virtualization must be disabled. Both examples are valid bootsectors and can be installed to virtual machine as floppy images; when booting from such floppy, in first case VirtualBox goes to 'Guru Meditation' VERR_TRPM_DONT_PANIC (VBox.log is attached, VBox.png contains black screen). The second example after access to page 0x8000 (through 'in al, dx' from ring-3, which loads allowed i/o ports bitmap, causing read from TSS) checks 'Accessed' bit of page 0x9000 and displays the letter 'M' at top-left corner of the screen.

Attachments

VBox.log Download (146.4 KB) - added by diamond 5 years ago.
1.bin Download (512 bytes) - added by diamond 5 years ago.
bootsector, which causes guru meditation
2.bin Download (512 bytes) - added by diamond 5 years ago.
bootsector, which displays unexpected modification

Change History

Changed 5 years ago by diamond

Changed 5 years ago by diamond

bootsector, which causes guru meditation

Changed 5 years ago by diamond

bootsector, which displays unexpected modification

comment:1 Changed 5 years ago by sandervl73

  • Summary changed from Incorrect handling of 'Accessed' bit in page table entries to Incorrect handling of 'Accessed' bit in page table entries -> fixed in SVN/3.0.10

Thanks for the detailed report! Fixed in SVN.

comment:2 Changed 4 years ago by frank

  • Status changed from new to closed
  • Resolution set to fixed
Note: See TracTickets for help on using tickets.

www.oracle.com
ContactPrivacy policyTerms of Use