Blame SOURCES/0065-Fix-buffer-overrun-due-DEFAULT_LOADER-length-miscalc.patch

ec51ad
From ac610fe45491deccaab2c4ee689cbbdac117930a Mon Sep 17 00:00:00 2001
ec51ad
From: Javier Martinez Canillas <javierm@redhat.com>
ec51ad
Date: Tue, 8 Sep 2020 12:26:45 +0200
ec51ad
Subject: [PATCH] Fix buffer overrun due DEFAULT_LOADER length miscalculation
ec51ad
ec51ad
The DEFAULT_LOADER is a UCS-2 string and the StrLen() function returns the
ec51ad
number of UCS-2 encoded characters in the string. But the allocated memory
ec51ad
is in bytes, so only half of the needed memory to store it is allocated.
ec51ad
ec51ad
This leads to a buffer overrun when the StrCpy() function attempts to copy
ec51ad
the DEFAULT_LOADER to the allocated buffer.
ec51ad
ec51ad
Fixes: 354bd9b1931 ("Actually check for errors from set_second_stage()")
ec51ad
Reported-by: Stuart Hayes <stuart_hayes@dell.com>
ec51ad
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
ec51ad
---
ec51ad
 shim.c | 3 ++-
ec51ad
 1 file changed, 2 insertions(+), 1 deletion(-)
ec51ad
ec51ad
diff --git a/shim.c b/shim.c
ec51ad
index 34dce25c330..82913c934f6 100644
ec51ad
--- a/shim.c
ec51ad
+++ b/shim.c
ec51ad
@@ -2096,8 +2096,9 @@ EFI_STATUS set_second_stage (EFI_HANDLE image_handle)
ec51ad
 	unsigned int i;
ec51ad
 	UINTN second_stage_len;
ec51ad
 
ec51ad
-	second_stage_len = StrLen(DEFAULT_LOADER) + 1;
ec51ad
+	second_stage_len = (StrLen(DEFAULT_LOADER) + 1) * sizeof(CHAR16);
ec51ad
 	second_stage = AllocatePool(second_stage_len);
ec51ad
+
ec51ad
 	if (!second_stage) {
ec51ad
 		perror(L"Could not allocate %lu bytes\n", second_stage_len);
ec51ad
 		return EFI_OUT_OF_RESOURCES;
ec51ad
-- 
ec51ad
2.28.0
ec51ad