From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from phobos.denx.de (phobos.denx.de [85.214.62.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id ECF78C04A6A for ; Thu, 27 Jul 2023 14:30:18 +0000 (UTC) Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 1E5D08682A; Thu, 27 Jul 2023 16:30:14 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="brSTVcTx"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id 2498286437; Thu, 27 Jul 2023 09:11:47 +0200 (CEST) Received: from mail-wm1-x32e.google.com (mail-wm1-x32e.google.com [IPv6:2a00:1450:4864:20::32e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 6021986768 for ; Thu, 27 Jul 2023 09:11:42 +0200 (CEST) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=dan.carpenter@linaro.org Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-3fc0aecf15bso6819125e9.1 for ; Thu, 27 Jul 2023 00:11:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1690441902; x=1691046702; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :from:to:cc:subject:date:message-id:reply-to; bh=0HtnVr9eyzXUTRpreJTIMIVF0B3HArR4U3wDpfNc/pY=; b=brSTVcTxU9zgeo9Pc/7u8YD+6WYn4iZkDc4VVRAf7j7Rr7uIzTlYL/1gm0c5N2MApv CEIQ08g2LfjX6C6plugZIEbieODKo4zWQhzydnz9hewlYnj6+O9vb4pMM/JI6PgSNxUg b3BZSa8AXTKym+879aslZDPglp9fRcBcP5z67OycDMgIjws4lVQHIG418PP0f3td+7k/ QRQTMJWXJ4HswZbRWuB70+JtvV+yjDe8pm0hYg6Zp8+IC+W7ByO5vl8qx8NmQSK40tmH 551y8MDtSp3n3bTcvPMArdmBL4pfQXNLB/3YLR/Rt7AC7iKwFuTXuCQI6lVBDboxpIxj T9yA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1690441902; x=1691046702; h=content-disposition:mime-version:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=0HtnVr9eyzXUTRpreJTIMIVF0B3HArR4U3wDpfNc/pY=; b=l7DdjS538XcNh47sPZfWe4nUWo/3FJkL3K26VHVfWFOEvA55d2JZ32dxlsUuQIx8gi /OPKs0r+rWY1vTSM0oEPqlEQ6227ZxEvHb6DcXHyOporP8YKTLqd80FeL70gZR4g67zA uVMY7nEoH1exZ1PDseP2snZUFcfXXnvJCPFCMxf/XD+qZV8u7xQ1lkIEQaSIBn/3BXT/ eOW0saGOnoXq42YHOmZSXjPSd8+AcH2lnhKGjkkcxkfR/KEMQ04KpHwBdLh6DTuGH4oD U7UgCPkwNEvYfMLu+pruz6QlSL9VbormcWrusl/CHU03QLViJaCfvrjTr47Kg21+zhd/ LFMw== X-Gm-Message-State: ABy/qLYg+PTec5yo7HKSCqCnHiADnd7SH9Y57uFdiRZXWNyJvOvmZ2FL HfRiA37/i0yglCouYkDEApGhFA== X-Google-Smtp-Source: APBJJlEeSSEI8u6upLR2afUQ4Y9YJUdPSm58DTMNupBPNk8425QJ4K+gx9QzQ5GLhHfxqCEJLNBUIA== X-Received: by 2002:a05:6000:7:b0:314:3856:8d99 with SMTP id h7-20020a056000000700b0031438568d99mr1084700wrx.44.1690441901672; Thu, 27 Jul 2023 00:11:41 -0700 (PDT) Received: from localhost ([102.36.222.112]) by smtp.gmail.com with ESMTPSA id f13-20020adfdb4d000000b003141e9e2f81sm1160001wrj.4.2023.07.27.00.11.40 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 27 Jul 2023 00:11:40 -0700 (PDT) Date: Thu, 27 Jul 2023 10:11:37 +0300 From: Dan Carpenter To: Heinrich Schuchardt Cc: Ilias Apalodimas , u-boot@lists.denx.de Subject: [PATCH v2] efi_loader: Fix memory corruption on 32bit systems Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline X-Mailer: git-send-email haha only kidding X-Mailman-Approved-At: Thu, 27 Jul 2023 16:29:59 +0200 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean The issue is this line: new_efi = efi_prepare_aligned_image(efi, (u64 *)&efi_size); The efi_size variable is type size_t and on a 32 bit system that's 32 bits. The u64 type is obviously 64 bits. So we write 8 bytes to a 4 byte buffer which corrupts memory. Fix this by changing the type of efi_prepare_aligned_image() to a size_t pointer. Signed-off-by: Dan Carpenter --- v2: Change efi_prepare_aligned_image() instead of changing efi_image_authenticate(). This is a cleaner way to fix the problem. include/efi_loader.h | 2 +- lib/efi_loader/efi_image_loader.c | 4 ++-- lib/efi_loader/efi_tcg2.c | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/include/efi_loader.h b/include/efi_loader.h index b5fa0fe01ded..9c1a9ed16af6 100644 --- a/include/efi_loader.h +++ b/include/efi_loader.h @@ -1022,7 +1022,7 @@ bool efi_secure_boot_enabled(void); bool efi_capsule_auth_enabled(void); -void *efi_prepare_aligned_image(void *efi, u64 *efi_size); +void *efi_prepare_aligned_image(void *efi, size_t *efi_size); bool efi_image_parse(void *efi, size_t len, struct efi_image_regions **regp, WIN_CERTIFICATE **auth, size_t *auth_len); diff --git a/lib/efi_loader/efi_image_loader.c b/lib/efi_loader/efi_image_loader.c index 26df0da16c93..64980008403b 100644 --- a/lib/efi_loader/efi_image_loader.c +++ b/lib/efi_loader/efi_image_loader.c @@ -313,7 +313,7 @@ static int cmp_pe_section(const void *arg1, const void *arg2) * * Return: valid pointer to a image, return NULL if allocation fails. */ -void *efi_prepare_aligned_image(void *efi, u64 *efi_size) +void *efi_prepare_aligned_image(void *efi, size_t *efi_size) { size_t new_efi_size; void *new_efi; @@ -600,7 +600,7 @@ static bool efi_image_authenticate(void *efi, size_t efi_size) if (!efi_secure_boot_enabled()) return true; - new_efi = efi_prepare_aligned_image(efi, (u64 *)&efi_size); + new_efi = efi_prepare_aligned_image(efi, &efi_size); if (!new_efi) return false; diff --git a/lib/efi_loader/efi_tcg2.c b/lib/efi_loader/efi_tcg2.c index 49f8a5e77cbf..d57afd0c498b 100644 --- a/lib/efi_loader/efi_tcg2.c +++ b/lib/efi_loader/efi_tcg2.c @@ -882,7 +882,7 @@ out: * * Return: status code */ -static efi_status_t tcg2_hash_pe_image(void *efi, u64 efi_size, +static efi_status_t tcg2_hash_pe_image(void *efi, size_t efi_size, struct tpml_digest_values *digest_list) { WIN_CERTIFICATE *wincerts = NULL; -- 2.39.2