mirror of
https://codeberg.org/libreboot/lbmk.git
synced 2026-07-25 07:46:17 +02:00
e348ea0381
You can find information about these patches here:
https://lists.gnu.org/archive/html/grub-devel/2025-02/msg00024.html
GRUB has been on a crusade as of late, to proactively audit
and fix many security vulnerabilities. This lbmk change brings
in a comprehensive series of patches that fix bugs ranging from
possible buffer overflows, use-after frees, null derefs and so on.
These changes are critical, so a revision release *will* be issued,
for the Libreboot 20241206 release series.
This change imports the following 73 patches which
are present on the upstream GRUB repository (commit IDs
matched to upstream):
* 4dc616657 loader/i386/bsd: Use safe math to avoid underflow
* 490a6ab71 loader/i386/linux: Cast left shift to grub_uint32_t
* a8d6b0633 kern/misc: Add sanity check after grub_strtoul() call
* 8e6e87e79 kern/partition: Add sanity check after grub_strtoul() call
* 5b36a5210 normal/menu: Use safe math to avoid an integer overflow
* 9907d9c27 bus/usb/ehci: Define GRUB_EHCI_TOGGLE as grub_uint32_t
* f8795cde2 misc: Ensure consistent overflow error messages
* 66733f7c7 osdep/unix/getroot: Fix potential underflow
* d13b6e8eb script/execute: Fix potential underflow and NULL dereference
* e3c578a56 fs/sfs: Check if allocated memory is NULL
* 1c06ec900 net: Check if returned pointer for allocated memory is NULL
* dee2c14fd net: Prevent overflows when allocating memory for arrays
* 4beeff8a3 net: Use safe math macros to prevent overflows
* dd6a4c8d1 fs/zfs: Add missing NULL check after grub_strdup() call
* 13065f69d fs/zfs: Check if returned pointer for allocated memory is NULL
* 7f38e32c7 fs/zfs: Prevent overflows when allocating memory for arrays
* 88e491a0f fs/zfs: Use safe math macros to prevent overflows
* cde9f7f33 fs: Prevent overflows when assigning returned values from read_number()
* 84bc0a9a6 fs: Prevent overflows when allocating memory for arrays
* 6608163b0 fs: Use safe math macros to prevent overflows
* fbaddcca5 disk/ieee1275/ofdisk: Call grub_ieee1275_close() when grub_malloc() fails
* 33bd6b5ac disk: Check if returned pointer for allocated memory is NULL
* d8151f983 disk: Prevent overflows when allocating memory for arrays
* c407724da disk: Use safe math macros to prevent overflows
* c4bc55da2 fs: Disable many filesystems under lockdown
* 26db66050 fs/bfs: Disable under lockdown
* 5f31164ae commands/hexdump: Disable memory reading in lockdown mode
* 340e4d058 commands/memrw: Disable memory reading in lockdown mode
* 34824806a commands/minicmd: Block the dump command in lockdown mode
* c68b7d236 commands/test: Stack overflow due to unlimited recursion depth
* dad8f5029 commands/read: Fix an integer overflow when supplying more than 2^31 characters
* b970a5ed9 gettext: Integer overflow leads to heap OOB write
* 09bd6eb58 gettext: Integer overflow leads to heap OOB write or read
* 7580addfc gettext: Remove variables hooks on module unload
* 9c1619773 normal: Remove variables hooks on module unload
* 2123c5bca commands/pgp: Unregister the "check_signatures" hooks on module unload
* 0bf56bce4 commands/ls: Fix NULL dereference
* 05be856a8 commands/extcmd: Missing check for failed allocation
* 98ad84328 kern/dl: Check for the SHF_INFO_LINK flag in grub_dl_relocate_symbols()
* d72208423 kern/dl: Use correct segment in grub_dl_set_mem_attrs()
* 500e5fdd8 kern/dl: Fix for an integer overflow in grub_dl_ref()
* 2c34af908 video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG
* 0707accab net/tftp: Fix stack buffer overflow in tftp_open()
* 5eef88152 net: Fix OOB write in grub_net_search_config_file()
* aa8b4d7fa net: Remove variables hooks when interface is unregisted
* a1dd8e59d net: Unregister net_default_ip and net_default_mac variables hooks on unload
* d8a937cca script/execute: Limit the recursion depth
* 8a7103fdd kern/partition: Limit recursion in part_iterate()
* 18212f064 kern/disk: Limit recursion depth
* 67f70f70a disk/loopback: Reference tracking for the loopback
* 13febd78d disk/cryptodisk: Require authentication after TPM unlock for CLI access
* 16f196874 kern/file: Implement filesystem reference counting
* a79106872 kern/file: Ensure file->data is set
* d1d6b7ea5 fs/xfs: Ensuring failing to mount sets a grub_errno
* 6ccc77b59 fs/xfs: Fix out-of-bounds read
* 067b6d225 fs/ntfs: Implement attribute verification
* 048777bc2 fs/ntfs: Use a helper function to access attributes
* 237a71184 fs/ntfs: Track the end of the MFT attribute buffer
* aff263187 fs/ntfs: Fix out-of-bounds read
* 7e2f750f0 fs/ext2: Fix out-of-bounds read for inline extents
* edd995a26 fs/jfs: Inconsistent signed/unsigned types usage in return values
* bd999310f fs/jfs: Use full 40 bits offset and address for a data extent
* ab09fd053 fs/jfs: Fix OOB read caused by invalid dir slot index
* 66175696f fs/jfs: Fix OOB read in jfs_getent()
* 1443833a9 fs/iso9660: Fix invalid free
* 965db5970 fs/iso9660: Set a grub_errno if mount fails
* f7c070a2e fs/hfsplus: Set a grub_errno if mount fails
* 563436258 fs/f2fs: Set a grub_errno if mount fails
* 0087bc690 fs/tar: Integer overflow leads to heap OOB write
* 2c8ac08c9 fs/tar: Initialize name in grub_cpio_find_file()
* 417547c10 fs/hfs: Fix stack OOB write with grub_strcpy()
* c1a291b01 fs/ufs: Fix a heap OOB write
* ea703528a misc: Implement grub_strlcpy()
Signed-off-by: Leah Rowe <leah@libreboot.org>
247 lines
8.6 KiB
Diff
247 lines
8.6 KiB
Diff
From 2472f3c2e465863c51a3cacf96ab910c015cfa8e Mon Sep 17 00:00:00 2001
|
|
From: Patrick Rudolph <patrick.rudolph@9elements.com>
|
|
Date: Sun, 15 Nov 2020 19:00:27 +0100
|
|
Subject: [PATCH 14/26] grub-core/bus/usb: Parse SuperSpeed companion
|
|
descriptors
|
|
|
|
Parse the SS_ENDPOINT_COMPANION descriptor, which is only present on USB 3.0
|
|
capable devices and xHCI controllers. Make the descendp an array of pointers
|
|
to the endpoint descriptor as it's no longer an continous array.
|
|
|
|
Signed-off-by: Patrick Rudolph <patrick.rudolph@9elements.com>
|
|
---
|
|
grub-core/bus/usb/serial/common.c | 2 +-
|
|
grub-core/bus/usb/usb.c | 44 +++++++++++++++++++------------
|
|
grub-core/bus/usb/usbhub.c | 22 ++++++++++++----
|
|
grub-core/commands/usbtest.c | 2 +-
|
|
grub-core/disk/usbms.c | 2 +-
|
|
grub-core/term/usb_keyboard.c | 2 +-
|
|
include/grub/usb.h | 2 +-
|
|
include/grub/usbdesc.h | 11 +++++++-
|
|
8 files changed, 59 insertions(+), 28 deletions(-)
|
|
|
|
diff --git a/grub-core/bus/usb/serial/common.c b/grub-core/bus/usb/serial/common.c
|
|
index e9c995a0a..fc847d66d 100644
|
|
--- a/grub-core/bus/usb/serial/common.c
|
|
+++ b/grub-core/bus/usb/serial/common.c
|
|
@@ -72,7 +72,7 @@ grub_usbserial_attach (grub_usb_device_t usbdev, int configno, int interfno,
|
|
for (j = 0; j < interf->endpointcnt; j++)
|
|
{
|
|
struct grub_usb_desc_endp *endp;
|
|
- endp = &usbdev->config[0].interf[interfno].descendp[j];
|
|
+ endp = usbdev->config[0].interf[interfno].descendp[j];
|
|
|
|
if ((endp->endp_addr & 128) && (endp->attrib & 3) == 2
|
|
&& (in_endp == GRUB_USB_SERIAL_ENDPOINT_LAST_MATCHING
|
|
diff --git a/grub-core/bus/usb/usb.c b/grub-core/bus/usb/usb.c
|
|
index 7bd49d201..e578af793 100644
|
|
--- a/grub-core/bus/usb/usb.c
|
|
+++ b/grub-core/bus/usb/usb.c
|
|
@@ -118,7 +118,7 @@ grub_usb_device_initialize (grub_usb_device_t dev)
|
|
struct grub_usb_desc_device *descdev;
|
|
struct grub_usb_desc_config config;
|
|
grub_usb_err_t err;
|
|
- int i;
|
|
+ int i, j;
|
|
|
|
/* First we have to read first 8 bytes only and determine
|
|
* max. size of packet */
|
|
@@ -152,6 +152,7 @@ grub_usb_device_initialize (grub_usb_device_t dev)
|
|
int currif;
|
|
char *data;
|
|
struct grub_usb_desc *desc;
|
|
+ struct grub_usb_desc_endp *endp;
|
|
|
|
/* First just read the first 4 bytes of the configuration
|
|
descriptor, after that it is known how many bytes really have
|
|
@@ -201,24 +202,27 @@ grub_usb_device_initialize (grub_usb_device_t dev)
|
|
= (struct grub_usb_desc_if *) &data[pos];
|
|
pos += dev->config[i].interf[currif].descif->length;
|
|
|
|
+ dev->config[i].interf[currif].descendp = grub_malloc (
|
|
+ dev->config[i].interf[currif].descif->endpointcnt *
|
|
+ sizeof(struct grub_usb_desc_endp));
|
|
+
|
|
+ j = 0;
|
|
while (pos < config.totallen)
|
|
{
|
|
desc = (struct grub_usb_desc *)&data[pos];
|
|
- if (desc->type == GRUB_USB_DESCRIPTOR_ENDPOINT)
|
|
- break;
|
|
- if (!desc->length)
|
|
- {
|
|
- err = GRUB_USB_ERR_BADDEVICE;
|
|
- goto fail;
|
|
- }
|
|
- pos += desc->length;
|
|
- }
|
|
-
|
|
- /* Point to the first endpoint. */
|
|
- dev->config[i].interf[currif].descendp
|
|
- = (struct grub_usb_desc_endp *) &data[pos];
|
|
- pos += (sizeof (struct grub_usb_desc_endp)
|
|
- * dev->config[i].interf[currif].descif->endpointcnt);
|
|
+ if (desc->type == GRUB_USB_DESCRIPTOR_ENDPOINT) {
|
|
+ endp = (struct grub_usb_desc_endp *) &data[pos];
|
|
+ dev->config[i].interf[currif].descendp[j++] = endp;
|
|
+ pos += desc->length;
|
|
+ } else {
|
|
+ if (!desc->length)
|
|
+ {
|
|
+ err = GRUB_USB_ERR_BADDEVICE;
|
|
+ goto fail;
|
|
+ }
|
|
+ pos += desc->length;
|
|
+ }
|
|
+ }
|
|
}
|
|
}
|
|
|
|
@@ -226,8 +230,14 @@ grub_usb_device_initialize (grub_usb_device_t dev)
|
|
|
|
fail:
|
|
|
|
- for (i = 0; i < GRUB_USB_MAX_CONF; i++)
|
|
+ for (i = 0; i < GRUB_USB_MAX_CONF; i++) {
|
|
+ int currif;
|
|
+
|
|
+ for (currif = 0; currif < dev->config[i].descconf->numif; currif++)
|
|
+ grub_free (dev->config[i].interf[currif].descendp);
|
|
+
|
|
grub_free (dev->config[i].descconf);
|
|
+ }
|
|
|
|
return err;
|
|
}
|
|
diff --git a/grub-core/bus/usb/usbhub.c b/grub-core/bus/usb/usbhub.c
|
|
index f5608e330..2ae29cba1 100644
|
|
--- a/grub-core/bus/usb/usbhub.c
|
|
+++ b/grub-core/bus/usb/usbhub.c
|
|
@@ -82,8 +82,14 @@ grub_usb_hub_add_dev (grub_usb_controller_t controller,
|
|
if (i == GRUB_USBHUB_MAX_DEVICES)
|
|
{
|
|
grub_error (GRUB_ERR_IO, "can't assign address to USB device");
|
|
- for (i = 0; i < GRUB_USB_MAX_CONF; i++)
|
|
- grub_free (dev->config[i].descconf);
|
|
+ for (i = 0; i < GRUB_USB_MAX_CONF; i++) {
|
|
+ int currif;
|
|
+
|
|
+ for (currif = 0; currif < dev->config[i].descconf->numif; currif++)
|
|
+ grub_free (dev->config[i].interf[currif].descendp);
|
|
+
|
|
+ grub_free (dev->config[i].descconf);
|
|
+ }
|
|
grub_free (dev);
|
|
return NULL;
|
|
}
|
|
@@ -96,8 +102,14 @@ grub_usb_hub_add_dev (grub_usb_controller_t controller,
|
|
i, 0, 0, NULL);
|
|
if (err)
|
|
{
|
|
- for (i = 0; i < GRUB_USB_MAX_CONF; i++)
|
|
- grub_free (dev->config[i].descconf);
|
|
+ for (i = 0; i < GRUB_USB_MAX_CONF; i++) {
|
|
+ int currif;
|
|
+
|
|
+ for (currif = 0; currif < dev->config[i].descconf->numif; currif++)
|
|
+ grub_free (dev->config[i].interf[currif].descendp);
|
|
+
|
|
+ grub_free (dev->config[i].descconf);
|
|
+ }
|
|
grub_free (dev);
|
|
return NULL;
|
|
}
|
|
@@ -176,7 +188,7 @@ grub_usb_add_hub (grub_usb_device_t dev)
|
|
i++)
|
|
{
|
|
struct grub_usb_desc_endp *endp = NULL;
|
|
- endp = &dev->config[0].interf[0].descendp[i];
|
|
+ endp = dev->config[0].interf[0].descendp[i];
|
|
|
|
if ((endp->endp_addr & 128) && grub_usb_get_ep_type(endp)
|
|
== GRUB_USB_EP_INTERRUPT)
|
|
diff --git a/grub-core/commands/usbtest.c b/grub-core/commands/usbtest.c
|
|
index 2c6d93fe6..55a657635 100644
|
|
--- a/grub-core/commands/usbtest.c
|
|
+++ b/grub-core/commands/usbtest.c
|
|
@@ -185,7 +185,7 @@ usb_iterate (grub_usb_device_t dev, void *data __attribute__ ((unused)))
|
|
for (j = 0; j < interf->endpointcnt; j++)
|
|
{
|
|
struct grub_usb_desc_endp *endp;
|
|
- endp = &dev->config[0].interf[i].descendp[j];
|
|
+ endp = dev->config[0].interf[i].descendp[j];
|
|
|
|
grub_printf ("Endpoint #%d: %s, max packed size: %d, transfer type: %s, latency: %d\n",
|
|
endp->endp_addr & 15,
|
|
diff --git a/grub-core/disk/usbms.c b/grub-core/disk/usbms.c
|
|
index b81e3ad9d..b1512dc12 100644
|
|
--- a/grub-core/disk/usbms.c
|
|
+++ b/grub-core/disk/usbms.c
|
|
@@ -184,7 +184,7 @@ grub_usbms_attach (grub_usb_device_t usbdev, int configno, int interfno)
|
|
for (j = 0; j < interf->endpointcnt; j++)
|
|
{
|
|
struct grub_usb_desc_endp *endp;
|
|
- endp = &usbdev->config[0].interf[interfno].descendp[j];
|
|
+ endp = usbdev->config[0].interf[interfno].descendp[j];
|
|
|
|
if ((endp->endp_addr & 128) && (endp->attrib & 3) == 2)
|
|
/* Bulk IN endpoint. */
|
|
diff --git a/grub-core/term/usb_keyboard.c b/grub-core/term/usb_keyboard.c
|
|
index 7322d8dff..d590979f5 100644
|
|
--- a/grub-core/term/usb_keyboard.c
|
|
+++ b/grub-core/term/usb_keyboard.c
|
|
@@ -175,7 +175,7 @@ grub_usb_keyboard_attach (grub_usb_device_t usbdev, int configno, int interfno)
|
|
for (j = 0; j < usbdev->config[configno].interf[interfno].descif->endpointcnt;
|
|
j++)
|
|
{
|
|
- endp = &usbdev->config[configno].interf[interfno].descendp[j];
|
|
+ endp = usbdev->config[configno].interf[interfno].descendp[j];
|
|
|
|
if ((endp->endp_addr & 128) && grub_usb_get_ep_type(endp)
|
|
== GRUB_USB_EP_INTERRUPT)
|
|
diff --git a/include/grub/usb.h b/include/grub/usb.h
|
|
index 0f346af12..688c11f6d 100644
|
|
--- a/include/grub/usb.h
|
|
+++ b/include/grub/usb.h
|
|
@@ -153,7 +153,7 @@ struct grub_usb_interface
|
|
{
|
|
struct grub_usb_desc_if *descif;
|
|
|
|
- struct grub_usb_desc_endp *descendp;
|
|
+ struct grub_usb_desc_endp **descendp;
|
|
|
|
/* A driver is handling this interface. Do we need to support multiple drivers
|
|
for single interface?
|
|
diff --git a/include/grub/usbdesc.h b/include/grub/usbdesc.h
|
|
index aac5ab05a..bb2ab2e27 100644
|
|
--- a/include/grub/usbdesc.h
|
|
+++ b/include/grub/usbdesc.h
|
|
@@ -29,7 +29,8 @@ typedef enum {
|
|
GRUB_USB_DESCRIPTOR_INTERFACE,
|
|
GRUB_USB_DESCRIPTOR_ENDPOINT,
|
|
GRUB_USB_DESCRIPTOR_DEBUG = 10,
|
|
- GRUB_USB_DESCRIPTOR_HUB = 0x29
|
|
+ GRUB_USB_DESCRIPTOR_HUB = 0x29,
|
|
+ GRUB_USB_DESCRIPTOR_SS_ENDPOINT_COMPANION = 0x30
|
|
} grub_usb_descriptor_t;
|
|
|
|
struct grub_usb_desc
|
|
@@ -105,6 +106,14 @@ struct grub_usb_desc_endp
|
|
grub_uint8_t interval;
|
|
} GRUB_PACKED;
|
|
|
|
+struct grub_usb_desc_ssep {
|
|
+ grub_uint8_t length;
|
|
+ grub_uint8_t type;
|
|
+ grub_uint8_t maxburst;
|
|
+ grub_uint8_t attrib;
|
|
+ grub_uint16_t interval;
|
|
+} GRUB_PACKED;
|
|
+
|
|
struct grub_usb_desc_str
|
|
{
|
|
grub_uint8_t length;
|
|
--
|
|
2.39.5
|
|
|