mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-08-01 21:23:51 -09:00
This patch brings the entire stack of Debian patches on grub2 titled "cve-2025-jan" and available at: https://salsa.debian.org/grub-team/grub/-/tree/debian/2.12-9/debian/patches/cve-2025-jan?ref_type=tags As of this exact Debian grub2 version 2.12-9. Some minor conflicts had to be fixed. All patches are in upstream Grub master, but mixed with hundreds of other changes, which is why Debian's effort to backport them has been leveraged here. In addition to those patches, 2 extra patches are added: 0073-net-drivers-ieee1275-ofnet-Add-missing-grub_malloc.patch 0074-Constant-time-grub_crypto_memcmp.patch The first one fixes an issue in one of the earlier patches. The fix is not in Debian, but is in upstream Grub. The second one fixes another CVE, not fixed in Debian, but fixed in OpenSUSE. This fix is not upstream as upstream has decided to move to libgcrypt instead to avoid the problem, but that's a fairly large change. Overall, this patch fixes all CVEs currently reported by pkg-stats against our grub2 package, namely: CVE-2024-45777 CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45782 CVE-2024-56737 CVE-2024-56738 CVE-2025-0678 CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-1125 With the previous fixes on runtime tests added (to use glibc toolchains to build grub2 tests), this commit successfully passes all tests: - The ISO9660 tests that use grub2: https://gitlab.com/tpetazzoni/buildroot/-/pipelines/1985234563 - The grub2 tests: https://gitlab.com/tpetazzoni/buildroot/-/pipelines/1985234685 Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com> [Julien: also tested by building and booting - qemu_aarch64_sbsa_defconfig - qemu_arm_ebbr_defconfig - qemu_loongarch64_virt_efi_defconfig - qemu_riscv64_virt_efi_defconfig - pc_x86_64_bios_defconfig - pc_x86_64_efi_defconfig ] Tested-by: Julien Olivain <ju.o@free.fr> [Julien: - fix patch #72 upstream link to point to the initial patch sumbission rather than a reply - merge two _IGNORE_CVES blocks for patch #50 into a single one - order _IGNORE_CVES blocks by numerical patch order - order numerically the CVE list in commit log - add a "Fixes:" tag in patch #74 since its commit log does not mention the CVE. ] Signed-off-by: Julien Olivain <ju.o@free.fr>
144 lines
4.4 KiB
Diff
144 lines
4.4 KiB
Diff
From 4d70ddc5255b6d3f752da4120f593d7007222ca2 Mon Sep 17 00:00:00 2001
|
|
From: B Horn <b@horn.uk>
|
|
Date: Thu, 18 Apr 2024 15:59:26 +0100
|
|
Subject: [PATCH] kern/dl: Fix for an integer overflow in grub_dl_ref()
|
|
|
|
It was possible to overflow the value of mod->ref_count, a signed
|
|
integer, by repeatedly invoking insmod on an already loaded module.
|
|
This led to a use-after-free. As once ref_count was overflowed it became
|
|
possible to unload the module while there was still references to it.
|
|
|
|
This resolves the issue by using grub_add() to check if the ref_count
|
|
will overflow and then stops further increments. Further changes were
|
|
also made to grub_dl_unref() to check for the underflow condition and
|
|
the reference count was changed to an unsigned 64-bit integer.
|
|
|
|
Reported-by: B Horn <b@horn.uk>
|
|
Signed-off-by: B Horn <b@horn.uk>
|
|
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
|
|
Upstream: 500e5fdd82ca40412b0b73f5e5dda38e4a3af96d
|
|
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
|
|
---
|
|
grub-core/commands/minicmd.c | 2 +-
|
|
grub-core/kern/dl.c | 17 ++++++++++++-----
|
|
include/grub/dl.h | 8 ++++----
|
|
util/misc.c | 4 ++--
|
|
4 files changed, 19 insertions(+), 12 deletions(-)
|
|
|
|
diff --git a/grub-core/commands/minicmd.c b/grub-core/commands/minicmd.c
|
|
index fa498931e..286290866 100644
|
|
--- a/grub-core/commands/minicmd.c
|
|
+++ b/grub-core/commands/minicmd.c
|
|
@@ -167,7 +167,7 @@ grub_mini_cmd_lsmod (struct grub_command *cmd __attribute__ ((unused)),
|
|
{
|
|
grub_dl_dep_t dep;
|
|
|
|
- grub_printf ("%s\t%d\t\t", mod->name, mod->ref_count);
|
|
+ grub_printf ("%s\t%" PRIuGRUB_UINT64_T "\t\t", mod->name, mod->ref_count);
|
|
for (dep = mod->dep; dep; dep = dep->next)
|
|
{
|
|
if (dep != mod->dep)
|
|
diff --git a/grub-core/kern/dl.c b/grub-core/kern/dl.c
|
|
index 0bf40caa6..1a38742e6 100644
|
|
--- a/grub-core/kern/dl.c
|
|
+++ b/grub-core/kern/dl.c
|
|
@@ -32,6 +32,7 @@
|
|
#include <grub/env.h>
|
|
#include <grub/cache.h>
|
|
#include <grub/i18n.h>
|
|
+#include <grub/safemath.h>
|
|
|
|
/* Platforms where modules are in a readonly area of memory. */
|
|
#if defined(GRUB_MACHINE_QEMU)
|
|
@@ -532,7 +533,7 @@ grub_dl_resolve_dependencies (grub_dl_t mod, Elf_Ehdr *e)
|
|
return GRUB_ERR_NONE;
|
|
}
|
|
|
|
-int
|
|
+grub_uint64_t
|
|
grub_dl_ref (grub_dl_t mod)
|
|
{
|
|
grub_dl_dep_t dep;
|
|
@@ -543,10 +544,13 @@ grub_dl_ref (grub_dl_t mod)
|
|
for (dep = mod->dep; dep; dep = dep->next)
|
|
grub_dl_ref (dep->mod);
|
|
|
|
- return ++mod->ref_count;
|
|
+ if (grub_add (mod->ref_count, 1, &mod->ref_count))
|
|
+ grub_fatal ("Module reference count overflow");
|
|
+
|
|
+ return mod->ref_count;
|
|
}
|
|
|
|
-int
|
|
+grub_uint64_t
|
|
grub_dl_unref (grub_dl_t mod)
|
|
{
|
|
grub_dl_dep_t dep;
|
|
@@ -557,10 +561,13 @@ grub_dl_unref (grub_dl_t mod)
|
|
for (dep = mod->dep; dep; dep = dep->next)
|
|
grub_dl_unref (dep->mod);
|
|
|
|
- return --mod->ref_count;
|
|
+ if (grub_sub (mod->ref_count, 1, &mod->ref_count))
|
|
+ grub_fatal ("Module reference count underflow");
|
|
+
|
|
+ return mod->ref_count;
|
|
}
|
|
|
|
-int
|
|
+grub_uint64_t
|
|
grub_dl_ref_count (grub_dl_t mod)
|
|
{
|
|
if (mod == NULL)
|
|
diff --git a/include/grub/dl.h b/include/grub/dl.h
|
|
index cd1f46c8b..f0a94e273 100644
|
|
--- a/include/grub/dl.h
|
|
+++ b/include/grub/dl.h
|
|
@@ -174,7 +174,7 @@ typedef struct grub_dl_dep *grub_dl_dep_t;
|
|
struct grub_dl
|
|
{
|
|
char *name;
|
|
- int ref_count;
|
|
+ grub_uint64_t ref_count;
|
|
int persistent;
|
|
grub_dl_dep_t dep;
|
|
grub_dl_segment_t segment;
|
|
@@ -203,9 +203,9 @@ grub_dl_t EXPORT_FUNC(grub_dl_load) (const char *name);
|
|
grub_dl_t grub_dl_load_core (void *addr, grub_size_t size);
|
|
grub_dl_t EXPORT_FUNC(grub_dl_load_core_noinit) (void *addr, grub_size_t size);
|
|
int EXPORT_FUNC(grub_dl_unload) (grub_dl_t mod);
|
|
-extern int EXPORT_FUNC(grub_dl_ref) (grub_dl_t mod);
|
|
-extern int EXPORT_FUNC(grub_dl_unref) (grub_dl_t mod);
|
|
-extern int EXPORT_FUNC(grub_dl_ref_count) (grub_dl_t mod);
|
|
+extern grub_uint64_t EXPORT_FUNC(grub_dl_ref) (grub_dl_t mod);
|
|
+extern grub_uint64_t EXPORT_FUNC(grub_dl_unref) (grub_dl_t mod);
|
|
+extern grub_uint64_t EXPORT_FUNC(grub_dl_ref_count) (grub_dl_t mod);
|
|
|
|
extern grub_dl_t EXPORT_VAR(grub_dl_head);
|
|
|
|
diff --git a/util/misc.c b/util/misc.c
|
|
index d545212d9..0f928e5b4 100644
|
|
--- a/util/misc.c
|
|
+++ b/util/misc.c
|
|
@@ -190,14 +190,14 @@ grub_xputs_real (const char *str)
|
|
|
|
void (*grub_xputs) (const char *str) = grub_xputs_real;
|
|
|
|
-int
|
|
+grub_uint64_t
|
|
grub_dl_ref (grub_dl_t mod)
|
|
{
|
|
(void) mod;
|
|
return 0;
|
|
}
|
|
|
|
-int
|
|
+grub_uint64_t
|
|
grub_dl_unref (grub_dl_t mod)
|
|
{
|
|
(void) mod;
|
|
--
|
|
2.50.1
|
|
|