|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH v2 1/2] EFI: avoid OOB config file reads
On Wed, Mar 25, 2026 at 2:24 PM Jan Beulich <jbeulich@xxxxxxxx> wrote:
> @@ -878,6 +882,23 @@ static bool __init read_section(const EF
>
> file->ptr = ptr;
>
> + /* For cfg file, if necessary allocate space to put an extra NUL there.
> */
> + if ( file == &cfg && file->size && !iscntrl(file->str[file->size - 1]) )
> + {
> + EFI_PHYSICAL_ADDRESS addr;
> + EFI_STATUS ret = efi_bs->AllocatePages(AllocateMaxAddress,
> + EfiLoaderData,
> + PFN_UP(file->size + 1),
> &addr);
efiapi.h lists the Memory parameter as OUT, but that seems to be a
mistake; the UEFI spec [1] says this is IN OUT; and the other two
callers of AllocatePages in Xen initialize the value before passing it
in. So we should probably fix both efiapi.h, and initialize this to
an appropriate value, rather than passing in stack rubble.
Discovered by sashiko+Opus.
-George
[1]
https://uefi.org/sites/default/files/resources/UEFI%20Spec%202.8B%20May%202020.pdf
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |