Re: [PATCH] x86/fpu: Avoid kernel-address leaks in the FXSAVE workaround
From: Borislav Petkov
Date: Tue Oct 06 2026 - 20:46:36 EST
On Tue, Oct 06, 2026 at 03:15:41PM -0700, Kyle Zeng wrote:
> On AMD CPUs without XSaveErPtr, restoring x87 state without a pending
> exception can leave FDP/FIP/FOP unchanged. The existing workaround
> replaces the previous context's pointers by executing FILD on a kernel
> fpstate. This exposes the kernel instruction and operand addresses
> instead. On TCG qemu64, an unprivileged task can recover the kernel
> text slide with FNSTENV at ELF entry, even though FXSAVE64 reports zero
> error pointers.
Is this where you basically prompt the LLM to find you any bug in the kernel,
no matter the relevance, as long as there is something?
Or do you also ask it to consider the practical relevance of the fix and
whether it is even worth doing it?
--
Regards/Gruss,
Boris.
https://people.kernel.org/tglx/notes-about-netiquette