From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1p5Yyk-0002BD-Il for mharc-grub-devel@gnu.org; Wed, 14 Dec 2022 16:07:50 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1p5WuQ-0006Zy-QK for grub-devel@gnu.org; Wed, 14 Dec 2022 13:55:14 -0500 Received: from mx0a-00069f02.pphosted.com ([205.220.165.32]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1p5WuO-0001DQ-SG for grub-devel@gnu.org; Wed, 14 Dec 2022 13:55:14 -0500 Received: from pps.filterd (m0333521.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 2BEHFfwn025185; Wed, 14 Dec 2022 18:55:07 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=from : to : cc : subject : date : message-id : mime-version : content-transfer-encoding; s=corp-2022-7-12; bh=exyHfqX3YBqBj4mgex0N+yufSRz6teS56I0+bof5oAY=; b=jqHctDEOOxuDPtk5m3UXTLT6nMnpyuYOBhSvj7DvzDG++IH2l8bR9ifaUDCEY2EkNYXK Dj/BEZXQKL4EI3kpQyEDO8NDFw3WZuTsuVyefydfYtVUuifiLuRtlLZlq9PwY1gOcaBP a3DFWxNI4RRwYswWKRrtFtPp7wA1l6XfcICytF41SynilLBilhtA6aVDCnxP87OVF1oX Rr990gf4rTRY1bBnPs8S8fJUAxXlgOcwxZIKz/9DuK1U/ZnK2qk6/DCnVcylRi9xR/2v onQRHBAz+EN62aICcdz65CXs1Jcfw7EmA9kr3VEMsGn2sFRbkCEcXyRdqV2GhPQZ5NJG UA== Received: from phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (phxpaimrmta02.appoci.oracle.com [147.154.114.232]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 3meyex33h6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 14 Dec 2022 18:55:06 +0000 Received: from pps.filterd (phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com [127.0.0.1]) by phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (8.17.1.5/8.17.1.5) with ESMTP id 2BEHS548018889; Wed, 14 Dec 2022 18:55:06 GMT Received: from pps.reinject (localhost [127.0.0.1]) by phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (PPS) with ESMTPS id 3meyeqg8bx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Wed, 14 Dec 2022 18:55:06 +0000 Received: from phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.17.1.5/8.17.1.5) with ESMTP id 2BEIt5Y1033646; Wed, 14 Dec 2022 18:55:05 GMT Received: from localhost (lidochen-ol8-1.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.250.72]) by phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (PPS) with ESMTP id 3meyeqg8b9-1; Wed, 14 Dec 2022 18:55:05 +0000 From: Lidong Chen To: grub-devel@gnu.org Cc: scdbackup@gmx.net, fengtao40@huawei.com, yanan@huawei.com, daniel.kiper@oracle.com, lichenca2005@gmail.com Subject: [PATCH 0/4] fs/iso9660: Fix out-of-bounds read Date: Wed, 14 Dec 2022 18:55:01 +0000 Message-Id: X-Mailer: git-send-email 2.31.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.205,Aquarius:18.0.923,Hydra:6.0.545,FMLib:17.11.122.1 definitions=2022-12-14_09,2022-12-14_01,2022-06-22_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 adultscore=0 bulkscore=0 mlxscore=0 phishscore=0 malwarescore=0 spamscore=0 mlxlogscore=671 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2212070000 definitions=main-2212140154 X-Proofpoint-GUID: _vIHU5Tbn2seNbz9vDVsL2bh_n9BraBk X-Proofpoint-ORIG-GUID: _vIHU5Tbn2seNbz9vDVsL2bh_n9BraBk Received-SPF: pass client-ip=205.220.165.32; envelope-from=lidong.chen@oracle.com; helo=mx0a-00069f02.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Wed, 14 Dec 2022 16:07:43 -0500 X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 14 Dec 2022 18:55:15 -0000 This patches set fix a few out-of-bound reads and an infinite loop in fs/iso9660. The main issues are that there is no validation for the SUSP/RRIP entry size and no check for the boundary before read. Lidong Chen (4): fs/iso9660: Add check to prevent infinite loop fs/iso9660: Prevent read past the end of system use area fs/iso9660: Avoid reading past the entry boundary fs/iso9660: Incorrect check for entry boudary grub-core/fs/iso9660.c | 91 +++++++++++++++++++++++++++++++++++++----- 1 file changed, 81 insertions(+), 10 deletions(-) -- 2.35.1