On Thu, Sep 10, 2026 at 10:59:35AM +0900, Masami Hiramatsu (Google) wrote:
> From: Masami Hiramatsu (Google) <[email protected]>
> 
> Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd
> with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer
> arithmetic:
> 
>     data = ((void *)hdr) - size;
> 
> to wrap around on 32-bit systems (or when pointer subtraction overflows).
> Because data wraps around, the subsequent bounds check:
> 
>     if ((unsigned long)data < initrd_start)
> 
> evaluates to false, bypassing the check. The kernel then calls
> xbc_calc_checksum(data, size), which attempts to read 4GB of memory,
> hitting unmapped pages and triggering a fatal kernel page fault during
> early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an
> unbounded 32-bit size can similarly bypass the initrd_start check.
> 
> Fix this by:
> 1. Ensuring the initrd is at least large enough to contain the bootconfig
>    footer and verifying hdr is within the initrd bounds.
> 2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
>    the available space between initrd_start and hdr before performing
>    pointer subtraction.
> 
> Fixes: de462e5f1071 ("bootconfig: Fix to remove bootconfig data from initrd 
> while boot")
> Cc: [email protected]
> Reported-by: Sashiko <[email protected]>
> Closes: 
> https://lore.kernel.org/all/[email protected]/
> Assisted-by: Antigravity:gemini-3.8-flash
> Signed-off-by: Masami Hiramatsu (Google) <[email protected]>

Reviewed-by: Breno Leitao <[email protected]>

Reply via email to