Hi Ahmad,

please use the new list address:

<[email protected]>

(added to cc). Dropped the old one <[email protected]> address
from cc

Thanks!

bye,
Heiko

On 05.10.26 23:34, Ahmad Fatoum wrote:
Hi.

I am quite ignorant about how Android Verified Boot works, but looking
through the code in both cmd/avb.c and bootmeth_android.c, I wonder how
this could not be susceptible to a TOCTOU attack:

- do_avb_verify_part() does avb_slot_verify() and then discards what it
verified with avb_slot_verify_data_free()

- run_avb_verification() leaks AvbSlotVerifyData *out_data and doesn't
   seem to use it anywhere

So it looks like an attacker able to interpose the storage device should
be trivially able to circumvent both of these? Am I missing something?

Cheers,
Ahmad


--
Nabla Software Engineering
HRB 40522 Augsburg
Phone: +49 821 45592596
E-Mail: [email protected]
Geschäftsführer : Stefano Babic

Reply via email to