Hi.

I am quite ignorant about how Android Verified Boot works, but looking
through the code in both cmd/avb.c and bootmeth_android.c, I wonder how
this could not be susceptible to a TOCTOU attack:

- do_avb_verify_part() does avb_slot_verify() and then discards what it
verified with avb_slot_verify_data_free()

- run_avb_verification() leaks AvbSlotVerifyData *out_data and doesn't
  seem to use it anywhere

So it looks like an attacker able to interpose the storage device should
be trivially able to circumvent both of these? Am I missing something?

Cheers,
Ahmad

-- 
Pengutronix e.K.                           |                             |
Steuerwalder Str. 21                       | http://www.pengutronix.de/  |
31137 Hildesheim, Germany                  | Phone: +49-5121-206917-0    |
Amtsgericht Hildesheim, HRA 2686           | Fax:   +49-5121-206917-5555 |

Reply via email to