On Thu, Sep 10, 2026 at 10:59:35AM +0900, Masami Hiramatsu (Google) wrote: > From: Masami Hiramatsu (Google) <[email protected]> > > Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd > with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer > arithmetic: > > data = ((void *)hdr) - size; > > to wrap around on 32-bit systems (or when pointer subtraction overflows). > Because data wraps around, the subsequent bounds check: > > if ((unsigned long)data < initrd_start) > > evaluates to false, bypassing the check. The kernel then calls > xbc_calc_checksum(data, size), which attempts to read 4GB of memory, > hitting unmapped pages and triggering a fatal kernel page fault during > early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an > unbounded 32-bit size can similarly bypass the initrd_start check. > > Fix this by: > 1. Ensuring the initrd is at least large enough to contain the bootconfig > footer and verifying hdr is within the initrd bounds. > 2. Checking that size does not exceed XBC_DATA_MAX and does not exceed > the available space between initrd_start and hdr before performing > pointer subtraction. > > Fixes: de462e5f1071 ("bootconfig: Fix to remove bootconfig data from initrd > while boot") > Cc: [email protected] > Reported-by: Sashiko <[email protected]> > Closes: > https://lore.kernel.org/all/[email protected]/ > Assisted-by: Antigravity:gemini-3.8-flash > Signed-off-by: Masami Hiramatsu (Google) <[email protected]>
Reviewed-by: Breno Leitao <[email protected]>
