All of lore.kernel.org
 help / color / mirror / Atom feed
From: Breno Leitao <leitao@debian.org>
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: "Andrew Morton" <akpm@linux-foundation.org>,
	"Christian Brauner" <brauner@kernel.org>,
	"Thomas Gleixner" <tglx@kernel.org>,
	"Ryan Roberts" <ryan.roberts@arm.com>,
	"Thomas Weißschuh" <thomas.weissschuh@linutronix.de>,
	"Douglas Anderson" <dianders@chromium.org>,
	"Huacai Chen" <chenhuacai@kernel.org>,
	"Mark Rutland" <mark.rutland@arm.com>,
	linux-kernel@vger.kernel.org, linux-trace-kernel@vger.kernel.org,
	"Sang-Heon Jeon" <ekffu200098@gmail.com>
Subject: Re: [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check
Date: Thu, 10 Sep 2026 03:05:12 -0700	[thread overview]
Message-ID: <aqKAzTzpqYmuj8Rm@gmail.com> (raw)
In-Reply-To: <178900557529.200943.11099215789605267709.stgit@devnote2>

On Thu, Sep 10, 2026 at 10:59:35AM +0900, Masami Hiramatsu (Google) wrote:
> From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
> 
> Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd
> with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer
> arithmetic:
> 
>     data = ((void *)hdr) - size;
> 
> to wrap around on 32-bit systems (or when pointer subtraction overflows).
> Because data wraps around, the subsequent bounds check:
> 
>     if ((unsigned long)data < initrd_start)
> 
> evaluates to false, bypassing the check. The kernel then calls
> xbc_calc_checksum(data, size), which attempts to read 4GB of memory,
> hitting unmapped pages and triggering a fatal kernel page fault during
> early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an
> unbounded 32-bit size can similarly bypass the initrd_start check.
> 
> Fix this by:
> 1. Ensuring the initrd is at least large enough to contain the bootconfig
>    footer and verifying hdr is within the initrd bounds.
> 2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
>    the available space between initrd_start and hdr before performing
>    pointer subtraction.
> 
> Fixes: de462e5f1071 ("bootconfig: Fix to remove bootconfig data from initrd while boot")
> Cc: stable@vger.kernel.org
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@smtp.kernel.org/
> Assisted-by: Antigravity:gemini-3.8-flash
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>

Reviewed-by: Breno Leitao <leitao@debian.org>

  parent reply	other threads:[~2026-09-10 10:05 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10  1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
2026-09-10  1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
2026-09-10 14:56   ` Breno Leitao
2026-09-10  1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
2026-09-10  2:09   ` sashiko-bot
2026-09-10 14:32     ` Masami Hiramatsu
2026-09-10 10:05   ` Breno Leitao [this message]
2026-09-10 14:33     ` Masami Hiramatsu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aqKAzTzpqYmuj8Rm@gmail.com \
    --to=leitao@debian.org \
    --cc=akpm@linux-foundation.org \
    --cc=brauner@kernel.org \
    --cc=chenhuacai@kernel.org \
    --cc=dianders@chromium.org \
    --cc=ekffu200098@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mark.rutland@arm.com \
    --cc=mhiramat@kernel.org \
    --cc=ryan.roberts@arm.com \
    --cc=tglx@kernel.org \
    --cc=thomas.weissschuh@linutronix.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.