mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
This patch brings the entire stack of Debian patches on grub2 titled "cve-2025-jan" and available at: https://salsa.debian.org/grub-team/grub/-/tree/debian/2.12-9/debian/patches/cve-2025-jan?ref_type=tags As of this exact Debian grub2 version 2.12-9. Some minor conflicts had to be fixed. All patches are in upstream Grub master, but mixed with hundreds of other changes, which is why Debian's effort to backport them has been leveraged here. In addition to those patches, 2 extra patches are added: 0073-net-drivers-ieee1275-ofnet-Add-missing-grub_malloc.patch 0074-Constant-time-grub_crypto_memcmp.patch The first one fixes an issue in one of the earlier patches. The fix is not in Debian, but is in upstream Grub. The second one fixes another CVE, not fixed in Debian, but fixed in OpenSUSE. This fix is not upstream as upstream has decided to move to libgcrypt instead to avoid the problem, but that's a fairly large change. Overall, this patch fixes all CVEs currently reported by pkg-stats against our grub2 package, namely: CVE-2024-45777 CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45782 CVE-2024-56737 CVE-2024-56738 CVE-2025-0678 CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-1125 With the previous fixes on runtime tests added (to use glibc toolchains to build grub2 tests), this commit successfully passes all tests: - The ISO9660 tests that use grub2: https://gitlab.com/tpetazzoni/buildroot/-/pipelines/1985234563 - The grub2 tests: https://gitlab.com/tpetazzoni/buildroot/-/pipelines/1985234685 Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> [Julien: also tested by building and booting - qemu_aarch64_sbsa_defconfig - qemu_arm_ebbr_defconfig - qemu_loongarch64_virt_efi_defconfig - qemu_riscv64_virt_efi_defconfig - pc_x86_64_bios_defconfig - pc_x86_64_efi_defconfig ] Tested-by: Julien Olivain <ju.o@free.fr> [Julien: - fix patch #72 upstream link to point to the initial patch sumbission rather than a reply - merge two _IGNORE_CVES blocks for patch #50 into a single one - order _IGNORE_CVES blocks by numerical patch order - order numerically the CVE list in commit log - add a "Fixes:" tag in patch #74 since its commit log does not mention the CVE. ] Signed-off-by: Julien Olivain <ju.o@free.fr>
126 lines
3.6 KiB
Diff
126 lines
3.6 KiB
Diff
From 195331a7a64c2a4ba754e2527ca8973012db68c9 Mon Sep 17 00:00:00 2001
|
|
From: B Horn <b@horn.uk>
|
|
Date: Sun, 12 May 2024 04:09:24 +0100
|
|
Subject: [PATCH] kern/disk: Limit recursion depth
|
|
|
|
The grub_disk_read() may trigger other disk reads, e.g. via loopbacks.
|
|
This may lead to very deep recursion which can corrupt the heap. So, fix
|
|
the issue by limiting reads depth.
|
|
|
|
Reported-by: B Horn <b@horn.uk>
|
|
Signed-off-by: B Horn <b@horn.uk>
|
|
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
|
Upstream: 18212f0648b6de7d71d4c8f41eb4d8b78b3a299b
|
|
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
|
---
|
|
grub-core/kern/disk.c | 27 ++++++++++++++++++++-------
|
|
include/grub/err.h | 3 ++-
|
|
2 files changed, 22 insertions(+), 8 deletions(-)
|
|
|
|
diff --git a/grub-core/kern/disk.c b/grub-core/kern/disk.c
|
|
index 1eda58fe9..82e04fd00 100644
|
|
--- a/grub-core/kern/disk.c
|
|
+++ b/grub-core/kern/disk.c
|
|
@@ -28,6 +28,10 @@
|
|
|
|
#define GRUB_CACHE_TIMEOUT 2
|
|
|
|
+/* Disk reads may trigger other disk reads. So, limit recursion depth. */
|
|
+#define MAX_READ_RECURSION_DEPTH 16
|
|
+static unsigned int read_recursion_depth = 0;
|
|
+
|
|
/* The last time the disk was used. */
|
|
static grub_uint64_t grub_last_time = 0;
|
|
|
|
@@ -417,6 +421,8 @@ grub_err_t
|
|
grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
|
grub_off_t offset, grub_size_t size, void *buf)
|
|
{
|
|
+ grub_err_t err = GRUB_ERR_NONE;
|
|
+
|
|
/* First of all, check if the region is within the disk. */
|
|
if (grub_disk_adjust_range (disk, §or, &offset, size) != GRUB_ERR_NONE)
|
|
{
|
|
@@ -427,12 +433,17 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
|
return grub_errno;
|
|
}
|
|
|
|
+ if (++read_recursion_depth >= MAX_READ_RECURSION_DEPTH)
|
|
+ {
|
|
+ grub_error (GRUB_ERR_RECURSION_DEPTH, "grub_disk_read(): Maximum recursion depth exceeded");
|
|
+ goto error;
|
|
+ }
|
|
+
|
|
/* First read until first cache boundary. */
|
|
if (offset || (sector & (GRUB_DISK_CACHE_SIZE - 1)))
|
|
{
|
|
grub_disk_addr_t start_sector;
|
|
grub_size_t pos;
|
|
- grub_err_t err;
|
|
grub_size_t len;
|
|
|
|
start_sector = sector & ~((grub_disk_addr_t) GRUB_DISK_CACHE_SIZE - 1);
|
|
@@ -444,7 +455,7 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
|
err = grub_disk_read_small (disk, start_sector,
|
|
offset + pos, len, buf);
|
|
if (err)
|
|
- return err;
|
|
+ goto error;
|
|
buf = (char *) buf + len;
|
|
size -= len;
|
|
offset += len;
|
|
@@ -457,7 +468,6 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
|
{
|
|
char *data = NULL;
|
|
grub_disk_addr_t agglomerate;
|
|
- grub_err_t err;
|
|
|
|
/* agglomerate read until we find a first cached entry. */
|
|
for (agglomerate = 0; agglomerate
|
|
@@ -493,7 +503,7 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
|
- disk->log_sector_size),
|
|
buf);
|
|
if (err)
|
|
- return err;
|
|
+ goto error;
|
|
|
|
for (i = 0; i < agglomerate; i ++)
|
|
grub_disk_cache_store (disk->dev->id, disk->id,
|
|
@@ -527,13 +537,16 @@ grub_disk_read (grub_disk_t disk, grub_disk_addr_t sector,
|
|
/* And now read the last part. */
|
|
if (size)
|
|
{
|
|
- grub_err_t err;
|
|
err = grub_disk_read_small (disk, sector, 0, size, buf);
|
|
if (err)
|
|
- return err;
|
|
+ goto error;
|
|
}
|
|
|
|
- return grub_errno;
|
|
+ err = grub_errno;
|
|
+
|
|
+ error:
|
|
+ read_recursion_depth--;
|
|
+ return err;
|
|
}
|
|
|
|
grub_uint64_t
|
|
diff --git a/include/grub/err.h b/include/grub/err.h
|
|
index b0e54e0a0..202fa8a7a 100644
|
|
--- a/include/grub/err.h
|
|
+++ b/include/grub/err.h
|
|
@@ -74,7 +74,8 @@ typedef enum
|
|
GRUB_ERR_EOF,
|
|
GRUB_ERR_BAD_SIGNATURE,
|
|
GRUB_ERR_BAD_FIRMWARE,
|
|
- GRUB_ERR_STILL_REFERENCED
|
|
+ GRUB_ERR_STILL_REFERENCED,
|
|
+ GRUB_ERR_RECURSION_DEPTH
|
|
}
|
|
grub_err_t;
|
|
|
|
--
|
|
2.50.1
|
|
|