All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] efi: Initialize canary to non-zero value
@ 2023-11-12  3:23 Glenn Washburn
  2023-11-12  7:22 ` Heinrich Schuchardt
  0 siblings, 1 reply; 7+ messages in thread
From: Glenn Washburn @ 2023-11-12  3:23 UTC (permalink / raw)
  To: grub-devel, Daniel Kiper; +Cc: Chris Coulson, Glenn Washburn

The canary, __stack_chk_guard, is in the BSS and so will get initialized to
zero if it is not explicitly initialized. If the UEFI firmware does not
support the RNG protocol, then the canary will not be randomized and will
be used as zero. This seems like a possibly easier value to write by an
attacker. Initialize canary to static random bytes, so that it is still
random when there is not RNG protocol.

Signed-off-by: Glenn Washburn <development@efficientek.com>
---
 grub-core/kern/efi/init.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/grub-core/kern/efi/init.c b/grub-core/kern/efi/init.c
index 0e28bea17a76..b85d98ca47fd 100644
--- a/grub-core/kern/efi/init.c
+++ b/grub-core/kern/efi/init.c
@@ -41,7 +41,7 @@ static grub_guid_t rng_protocol_guid = GRUB_EFI_RNG_PROTOCOL_GUID;
 
 static grub_efi_uint8_t stack_chk_guard_buf[32];
 
-grub_addr_t __stack_chk_guard;
+grub_addr_t __stack_chk_guard = (grub_addr_t) 0x92f2b7e2f193b25c;
 
 void __attribute__ ((noreturn))
 __stack_chk_fail (void)
-- 
2.34.1


_______________________________________________
Grub-devel mailing list
Grub-devel@gnu.org
https://lists.gnu.org/mailman/listinfo/grub-devel

^ permalink raw reply related	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2023-11-18 21:02 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-11-12  3:23 [PATCH] efi: Initialize canary to non-zero value Glenn Washburn
2023-11-12  7:22 ` Heinrich Schuchardt
2023-11-13 16:18   ` Daniel Kiper
2023-11-14  3:17     ` Glenn Washburn
2023-11-14  4:05       ` Dimitri John Ledkov
2023-11-18 21:02         ` Glenn Washburn
2023-11-18 21:01     ` Glenn Washburn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.