Hi Ahmad, please use the new list address:
<[email protected]> (added to cc). Dropped the old one <[email protected]> address from cc Thanks! bye, Heiko On 05.10.26 23:34, Ahmad Fatoum wrote:
Hi. I am quite ignorant about how Android Verified Boot works, but looking through the code in both cmd/avb.c and bootmeth_android.c, I wonder how this could not be susceptible to a TOCTOU attack: - do_avb_verify_part() does avb_slot_verify() and then discards what it verified with avb_slot_verify_data_free() - run_avb_verification() leaks AvbSlotVerifyData *out_data and doesn't seem to use it anywhere So it looks like an attacker able to interpose the storage device should be trivially able to circumvent both of these? Am I missing something? Cheers, Ahmad
-- Nabla Software Engineering HRB 40522 Augsburg Phone: +49 821 45592596 E-Mail: [email protected] Geschäftsführer : Stefano Babic
