Hello Paul, +-- On Fri, 15 Nov 2019, Paul Mackerras wrote --+ | Instead we need either to prevent src->output from being set to 3 or | greater, or else limit its value when it is used. I've sent a revised patch v2 for this. It is not clear if this issue can be misused from a guest running on PPC E500 platform. Considering E500 is mostly used for SoC/Embedded systems. ...wdyt? -- Prasad J Pandit / Red Hat Product Security Team 8685 545E B54C 486B C6EB 271E E285 8B5A F050 DE8D