On Thu, 10 Sep 2026 09:30:46 +0900 "Masami Hiramatsu (Google)" <[email protected]> wrote:
> From: Masami Hiramatsu (Google) <[email protected]> > > Sashiko reported that on 32-bit systems, if the size in the bootconfig > footer is corrupted such that adding BOOTCONFIG_FOOTER_SIZE wraps > around (for instance, if size is 0xFFFFFFFF), the size check in > load_xbc_from_initrd() can be bypassed: > > if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) { > pr_err("bootconfig size is too big\n"); > return -E2BIG; > } > > This would lead to load_xbc_fd() being called with a negative size, > resulting in an undersized allocation, heap overflow on read, and > out-of-bounds write on the terminating null byte. > > Avoid the integer overflow by checking whether size is greater than > stat.st_size - BOOTCONFIG_FOOTER_SIZE. Since stat.st_size is already > verified to be at least BOOTCONFIG_FOOTER_SIZE earlier in the function, > this subtraction will never underflow. > > Fixes: 950313ebf79c ("tools: bootconfig: Add bootconfig command") > Reported-by: Sashiko <[email protected]> > Closes: > https://lore.kernel.org/all/[email protected]/ > Assisted-by: Antigravity:gemini-3.8-flash OOps, I forgot to add: Cc: [email protected] Thanks, > Signed-off-by: Masami Hiramatsu (Google) <[email protected]> > --- > tools/bootconfig/main.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/tools/bootconfig/main.c b/tools/bootconfig/main.c > index 7dc9fff9b637..b380ad6777fa 100644 > --- a/tools/bootconfig/main.c > +++ b/tools/bootconfig/main.c > @@ -218,7 +218,7 @@ static int load_xbc_from_initrd(int fd, char **buf) > csum = le32toh(csum); > > /* Wrong size error */ > - if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) { > + if (size > stat.st_size - BOOTCONFIG_FOOTER_SIZE) { > pr_err("bootconfig size is too big\n"); > return -E2BIG; > } > -- Masami Hiramatsu (Google) <[email protected]>
