mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 13:18:36 -09:00
This patch brings the entire stack of Debian patches on grub2 titled "cve-2025-jan" and available at: https://salsa.debian.org/grub-team/grub/-/tree/debian/2.12-9/debian/patches/cve-2025-jan?ref_type=tags As of this exact Debian grub2 version 2.12-9. Some minor conflicts had to be fixed. All patches are in upstream Grub master, but mixed with hundreds of other changes, which is why Debian's effort to backport them has been leveraged here. In addition to those patches, 2 extra patches are added: 0073-net-drivers-ieee1275-ofnet-Add-missing-grub_malloc.patch 0074-Constant-time-grub_crypto_memcmp.patch The first one fixes an issue in one of the earlier patches. The fix is not in Debian, but is in upstream Grub. The second one fixes another CVE, not fixed in Debian, but fixed in OpenSUSE. This fix is not upstream as upstream has decided to move to libgcrypt instead to avoid the problem, but that's a fairly large change. Overall, this patch fixes all CVEs currently reported by pkg-stats against our grub2 package, namely: CVE-2024-45777 CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45782 CVE-2024-56737 CVE-2024-56738 CVE-2025-0678 CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-1125 With the previous fixes on runtime tests added (to use glibc toolchains to build grub2 tests), this commit successfully passes all tests: - The ISO9660 tests that use grub2: https://gitlab.com/tpetazzoni/buildroot/-/pipelines/1985234563 - The grub2 tests: https://gitlab.com/tpetazzoni/buildroot/-/pipelines/1985234685 Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> [Julien: also tested by building and booting - qemu_aarch64_sbsa_defconfig - qemu_arm_ebbr_defconfig - qemu_loongarch64_virt_efi_defconfig - qemu_riscv64_virt_efi_defconfig - pc_x86_64_bios_defconfig - pc_x86_64_efi_defconfig ] Tested-by: Julien Olivain <ju.o@free.fr> [Julien: - fix patch #72 upstream link to point to the initial patch sumbission rather than a reply - merge two _IGNORE_CVES blocks for patch #50 into a single one - order _IGNORE_CVES blocks by numerical patch order - order numerically the CVE list in commit log - add a "Fixes:" tag in patch #74 since its commit log does not mention the CVE. ] Signed-off-by: Julien Olivain <ju.o@free.fr>
70 lines
2.5 KiB
Diff
70 lines
2.5 KiB
Diff
From b35b73b9d779e88fb4e6f53fb10a5bfebf3475aa Mon Sep 17 00:00:00 2001
|
|
From: Lidong Chen <lidong.chen@oracle.com>
|
|
Date: Fri, 22 Nov 2024 06:28:00 +0000
|
|
Subject: [PATCH] fs/jfs: Fix OOB read caused by invalid dir slot index
|
|
|
|
While fuzz testing JFS with ASAN enabled an OOB read was detected in
|
|
grub_jfs_opendir(). The issue occurred due to an invalid directory slot
|
|
index in the first entry of the sorted directory slot array in the inode
|
|
directory header. The fix ensures the slot index is validated before
|
|
accessing it. Given that an internal or a leaf node in a directory B+
|
|
tree is a 4 KiB in size and each directory slot is always 32 bytes, the
|
|
max number of slots in a node is 128. The validation ensures that the
|
|
slot index doesn't exceed this limit.
|
|
|
|
[1] https://jfs.sourceforge.net/project/pub/jfslayout.pdf
|
|
|
|
JFS will allocate 4K of disk space for an internal node of the B+ tree.
|
|
An internal node looks the same as a leaf node.
|
|
- page 10
|
|
|
|
Fixed number of Directory Slots depending on the size of the node. These are
|
|
the slots to be used for storing the directory slot array and the directory
|
|
entries or router entries. A directory slot is always 32 bytes.
|
|
...
|
|
A Directory Slot Array which is a sorted array of indices to the directory
|
|
slots that are currently in use.
|
|
...
|
|
An internal or a leaf node in the directory B+ tree is a 4K page.
|
|
- page 25
|
|
|
|
Signed-off-by: Lidong Chen <lidong.chen@oracle.com>
|
|
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
|
Reviewed-by: Alec Brown <alec.r.brown@oracle.com>
|
|
Upstream: ab09fd0531f3523ac0ef833404526c98c08248f7
|
|
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
|
---
|
|
grub-core/fs/jfs.c | 9 +++++++++
|
|
1 file changed, 9 insertions(+)
|
|
|
|
diff --git a/grub-core/fs/jfs.c b/grub-core/fs/jfs.c
|
|
index 32dec7fb7..88fb884df 100644
|
|
--- a/grub-core/fs/jfs.c
|
|
+++ b/grub-core/fs/jfs.c
|
|
@@ -46,6 +46,7 @@ GRUB_MOD_LICENSE ("GPLv3+");
|
|
* https://jfs.sourceforge.net/project/pub/jfslayout.pdf
|
|
*/
|
|
#define GRUB_JFS_INODE_INLINE_ENTRIES 8
|
|
+#define GRUB_JFS_DIR_MAX_SLOTS 128
|
|
|
|
struct grub_jfs_sblock
|
|
{
|
|
@@ -481,6 +482,14 @@ grub_jfs_opendir (struct grub_jfs_data *data, struct grub_jfs_inode *inode)
|
|
return 0;
|
|
}
|
|
|
|
+ if (inode->dir.header.sorted[0] >= GRUB_JFS_DIR_MAX_SLOTS)
|
|
+ {
|
|
+ grub_error (GRUB_ERR_BAD_FS, N_("invalid directory slot index"));
|
|
+ grub_free (diro->dirpage);
|
|
+ grub_free (diro);
|
|
+ return 0;
|
|
+ }
|
|
+
|
|
blk = grub_le_to_cpu32 (de[inode->dir.header.sorted[0]].ex.blk2);
|
|
blk <<= (grub_le_to_cpu16 (data->sblock.log2_blksz) - GRUB_DISK_SECTOR_BITS);
|
|
|
|
--
|
|
2.50.1
|
|
|