From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from list by lists.gnu.org with archive (Exim 4.90_1) id 1pIxEv-0003eY-De for mharc-grub-devel@gnu.org; Fri, 20 Jan 2023 14:39:53 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pIxEs-0003dZ-Vm for grub-devel@gnu.org; Fri, 20 Jan 2023 14:39:51 -0500 Received: from mx0a-00069f02.pphosted.com ([205.220.165.32]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pIxEr-0006FZ-Ho for grub-devel@gnu.org; Fri, 20 Jan 2023 14:39:50 -0500 Received: from pps.filterd (m0333521.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 30KI3cVd030807; Fri, 20 Jan 2023 19:39:45 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=from : to : cc : subject : date : message-id : mime-version : content-transfer-encoding; s=corp-2022-7-12; bh=jme/4CTGeEVtpkP6YvfUFYE0Px2aKq0XkahRo5Slb/M=; b=0lU87mmgAoN78pPzx2RKjX4DO9RzpB/7wRrfRBIqD9eKwOuwgY/yzqyjfVfbanpG7rje 6AFJq7fdhdt5trbpFIvnx7EAnTly5J5D9avRcUPgnWoFlbLvT99bsJMJUYyhIWqIuRxq Y4sBeKle9Cb0ZqzgQhkAyxp0NlAmBAY6Ovq0vtJWx4/r+g67OLcsPZ0ssEhsrDHhox6l B2fhNBV7qKloqZcPI2xtCKLUj4vxjioR/LXvH6XpRQatCYqFmsLAjf05M7J34WoqjPSn vZM/LbVNm5kUuZGp2Hol00Yu7keOZtEbt6nVMYXA2Vq/89F1cGGiAYyALxG0zEIFWggi YA== Received: from iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta03.appoci.oracle.com [130.35.103.27]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 3n3kaanhea-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 20 Jan 2023 19:39:45 +0000 Received: from pps.filterd (iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (8.17.1.5/8.17.1.5) with ESMTP id 30KJcArC013552; Fri, 20 Jan 2023 19:39:43 GMT Received: from pps.reinject (localhost [127.0.0.1]) by iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTPS id 3n6qmfjsdu-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 20 Jan 2023 19:39:43 +0000 Received: from iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.17.1.5/8.17.1.5) with ESMTP id 30KJXKGx026327; Fri, 20 Jan 2023 19:39:43 GMT Received: from localhost (lidochen-ol8-1.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.250.72]) by iadpaimrmta03.imrmtpd1.prodappiadaev1.oraclevcn.com (PPS) with ESMTP id 3n6qmfjsdh-1; Fri, 20 Jan 2023 19:39:42 +0000 From: Lidong Chen To: grub-devel@gnu.org Cc: scdbackup@gmx.net, daniel.kiper@oracle.com, fengtao40@huawei.com, yanan@huawei.com, lichenca2005@gmail.com Subject: [PATCH v3 0/5] fs/iso9660: Fix out-of-bounds read Date: Fri, 20 Jan 2023 19:39:37 +0000 Message-Id: X-Mailer: git-send-email 2.31.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.219,Aquarius:18.0.930,Hydra:6.0.562,FMLib:17.11.122.1 definitions=2023-01-20_10,2023-01-20_01,2022-06-22_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=0 malwarescore=0 phishscore=0 adultscore=0 mlxscore=0 mlxlogscore=670 spamscore=0 bulkscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2212070000 definitions=main-2301200187 X-Proofpoint-GUID: Yq3gYlwpPk5vmNZKmK4MYPK3dZ9Hp55l X-Proofpoint-ORIG-GUID: Yq3gYlwpPk5vmNZKmK4MYPK3dZ9Hp55l Received-SPF: pass client-ip=205.220.165.32; envelope-from=lidong.chen@oracle.com; helo=mx0a-00069f02.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: grub-devel@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: The development of GNU GRUB List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 20 Jan 2023 19:39:51 -0000 This v3 patches set addressed v2 review comments for patch 5. There is no changes to patch 1 to 4. Tested patch 5, the fixes were able to detect the endless loop, and Grub exited accordingly. Lidong Chen (5): fs/iso9660: Add check to prevent infinite loop fs/iso9660: Prevent read past the end of system use area fs/iso9660: Avoid reading past the entry boundary fs/iso9660: Incorrect check for entry boundary fs/iso9660: Prevent skipping CE or ST at start of continuation area grub-core/fs/iso9660.c | 100 ++++++++++++++++++++++++++++++++++++++--- 1 file changed, 93 insertions(+), 7 deletions(-) -- 2.35.1