All of lore.kernel.org
 help / color / mirror / Atom feed
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: sashiko-bot@kernel.org, linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH] tools/bootconfig: Fix integer overflow in size check
Date: Thu, 10 Sep 2026 10:03:31 +0900	[thread overview]
Message-ID: <20260910100331.c2d39516cead6c1e1fd00f78@kernel.org> (raw)
In-Reply-To: <20260910004056.6FE9A1F000FF@smtp.kernel.org>

On Thu, 10 Sep 2026 00:40:55 +0000
sashiko-bot@kernel.org wrote:

> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [High] Incomplete Fix / Integer Truncation Leading to Heap Overflow
> --
> 
> commit 2d027c4ee8625f17122dea0afb65c1e4b21ae531
> Author: Masami Hiramatsu (Google) <mhiramat@kernel.org>
> 
>     tools/bootconfig: Fix integer overflow in size check
>     
>     This commit modifies the size check in load_xbc_from_initrd() to prevent
>     an integer overflow on 32-bit systems. It changes the condition to
>     subtract BOOTCONFIG_FOOTER_SIZE from stat.st_size instead of adding it
>     to the bootconfig size.
> 
>     Closes: https://lore.kernel.org/all/20260909161113.16C691F00A3A@smtp.kernel.org/
> 
> > diff --git a/tools/bootconfig/main.c b/tools/bootconfig/main.c
> > index 7dc9fff9b6370..b380ad6777faa 100644
> > --- a/tools/bootconfig/main.c
> > +++ b/tools/bootconfig/main.c
> > @@ -218,7 +218,7 @@ static int load_xbc_from_initrd(int fd, char **buf)
> >  	csum = le32toh(csum);
> >  
> >  	/* Wrong size error  */
> > -	if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
> > +	if (size > stat.st_size - BOOTCONFIG_FOOTER_SIZE) {
> 
> [Severity: High]
> This is a pre-existing issue, but the fix doesn't seem to completely resolve
> the integer truncation and heap overflow vulnerabilities.
> 
> Can this size check still be bypassed for large files? Since stat.st_size is a
> 64-bit off_t, if the file size is larger than 4.29 GB, stat.st_size -
> BOOTCONFIG_FOOTER_SIZE can exceed UINT32_MAX. A corrupted uint32_t size of
> 0xFFFFFFFF would bypass this check because it is always smaller than the
> right side.
> 
> If bypassed, does passing 0xFFFFFFFF to load_xbc_fd() cause an integer
> truncation and heap overflow?
> 
> tools/bootconfig/main.c:load_xbc_fd() {
>     ...
>     static int load_xbc_fd(int fd, char **buf, int size)
>     ...
>         *buf = malloc(size + 1);
>         if (!*buf)
>             return -ENOMEM;
>     
>         ret = read(fd, *buf, size);
>     ...
>         (*buf)[size] = '\0';
>     ...
> }
> 
> Because size is an int, 0xFFFFFFFF is truncated to -1. This results in
> malloc(0) which returns a valid heap chunk. The read() call then receives -1
> which gets cast to SIZE_MAX, overflowing the heap chunk. Finally, a null byte
> is written to a negative array index (-1), causing an out-of-bounds write.

This part should be fixed in v2. But below is another problem.

> 
> Does this same vulnerability also affect load_xbc_file() when processing
> standalone files >= 2GB?
> 
> tools/bootconfig/main.c:load_xbc_file() {
>     ...
>     ret = fstat(fd, &stat);
>     ...
>     ret = load_xbc_fd(fd, buf, stat.st_size);
>     ...
> }
> 
> This implicitly truncates the 64-bit off_t stat.st_size into the 32-bit int
> size parameter of load_xbc_fd().
> 
> >  		pr_err("bootconfig size is too big\n");
> >  		return -E2BIG;
> >  	}

OK, let me update the patch.

Thank you,

-- 
Masami Hiramatsu (Google) <mhiramat@kernel.org>

      reply	other threads:[~2026-09-10  1:03 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10  0:30 [PATCH] tools/bootconfig: Fix integer overflow in size check Masami Hiramatsu (Google)
2026-09-10  0:34 ` Masami Hiramatsu
2026-09-10  0:40 ` sashiko-bot
2026-09-10  1:03   ` Masami Hiramatsu [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260910100331.c2d39516cead6c1e1fd00f78@kernel.org \
    --to=mhiramat@kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=sashiko-bot@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.