2022
07.12

Xen TLB Flush Bypass

Xen’s _get_page_type() contains an ABAC cmpxchg() race, where the code incorrectly assumes that if it reads a specific type_info value, and then later cmpxchg() succeeds, the type_info can’t have changed in between.

No Comment.

Add Your Comment

You must be logged in to post a comment.