Hi. I am quite ignorant about how Android Verified Boot works, but looking through the code in both cmd/avb.c and bootmeth_android.c, I wonder how this could not be susceptible to a TOCTOU attack:
- do_avb_verify_part() does avb_slot_verify() and then discards what it verified with avb_slot_verify_data_free() - run_avb_verification() leaks AvbSlotVerifyData *out_data and doesn't seem to use it anywhere So it looks like an attacker able to interpose the storage device should be trivially able to circumvent both of these? Am I missing something? Cheers, Ahmad -- Pengutronix e.K. | | Steuerwalder Str. 21 | http://www.pengutronix.de/ | 31137 Hildesheim, Germany | Phone: +49-5121-206917-0 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |
