mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3 0/2] bootconfig: Fix integer overflow problems
@ 2026-09-10  1:59 Masami Hiramatsu (Google)
  2026-09-10  1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
  2026-09-10  1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
  0 siblings, 2 replies; 3+ messages in thread
From: Masami Hiramatsu (Google) @ 2026-09-10  1:59 UTC (permalink / raw)
  To: Masami Hiramatsu, Andrew Morton, Breno Leitao, Christian Brauner,
	Thomas Gleixner, Ryan Roberts, Thomas Weißschuh,
	Douglas Anderson, Huacai Chen
  Cc: Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon

Hi,

Here are patches to fix bootconfig size overflow issue. If there is a wrong
bootconfig size is recorded, it can bypass the size check in the tool and the
kernel.

The previous version only fixes tools, but Sashiko found the same issue in
the kernel. So this version add that fix.

Here is the previous version.

 https://lore.kernel.org/all/178900114498.187028.9558747732041210116.stgit@devnote2/

Thank you,

---

Masami Hiramatsu (Google) (2):
      tools/bootconfig: Fix integer overflow and truncation in size checks
      bootconfig: Fix integer overflow in initrd size check


 init/main.c             |   14 ++++++++++----
 tools/bootconfig/main.c |   13 ++++++++++++-
 2 files changed, 22 insertions(+), 5 deletions(-)

--
Masami Hiramatsu (Google) <mhiramat@kernel.org>

^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks
  2026-09-10  1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
@ 2026-09-10  1:59 ` Masami Hiramatsu (Google)
  2026-09-10  1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
  1 sibling, 0 replies; 3+ messages in thread
From: Masami Hiramatsu (Google) @ 2026-09-10  1:59 UTC (permalink / raw)
  To: Masami Hiramatsu, Andrew Morton, Breno Leitao, Christian Brauner,
	Thomas Gleixner, Ryan Roberts, Thomas Weißschuh,
	Douglas Anderson, Huacai Chen
  Cc: Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon

From: Masami Hiramatsu (Google) <mhiramat@kernel.org>

Sashiko reported that on 32-bit systems, if an attacker crafts size in
the bootconfig footer such that adding BOOTCONFIG_FOOTER_SIZE wraps around
(for instance, if size is 0xFFFFFFFF), the size check in
load_xbc_from_initrd() can be bypassed:

    if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
        pr_err("bootconfig size is too big\n");
        return -E2BIG;
    }

Furthermore, on 64-bit systems with an initrd > 4.29 GB, comparing a
corrupted 32-bit size (e.g. 0xFFFFFFFF) against
stat.st_size - BOOTCONFIG_FOOTER_SIZE can also bypass the check if
size is not bounded. Similarly, load_xbc_file() passes 64-bit stat.st_size
directly into the 32-bit int size parameter of load_xbc_fd(), truncating
large standalone files (>= 2GB).

In both cases, passing 0xFFFFFFFF to load_xbc_fd() truncates to -1,
resulting in malloc(0), an integer overflow in read(), and an
out-of-bounds null-byte write.

Fix this by:
1. Rejecting size > XBC_DATA_MAX or
   size > stat.st_size - BOOTCONFIG_FOOTER_SIZE in load_xbc_from_initrd().
2. Rejecting stat.st_size > XBC_DATA_MAX in load_xbc_file() before passing
   it to load_xbc_fd().
3. Checking size < 0 || size > XBC_DATA_MAX defensively in load_xbc_fd().

Fixes: 950313ebf79c ("tools: bootconfig: Add bootconfig command")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260909161113.16C691F00A3A@smtp.kernel.org/
Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@smtp.kernel.org/
Assisted-by: Antigravity:gemini-3.8-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
---
Changes in v3:
 - Reject size > XBC_DATA_MAX and
   size > stat.st_size - BOOTCONFIG_FOOTER_SIZE in load_xbc_from_initrd()
   to prevent bypass on initrd > 4.29 GB.
 - Check stat.st_size > XBC_DATA_MAX in load_xbc_file() to prevent
   truncation on large standalone files.
 - Check size < 0 || size > XBC_DATA_MAX defensively in load_xbc_fd().
Changes in v2:
  - Add Cc: stable.
  - Also reject if "size > XBC_DATA_MAX", that is obviously wrong.
---
 tools/bootconfig/main.c |   13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

diff --git a/tools/bootconfig/main.c b/tools/bootconfig/main.c
index 7dc9fff9b637..17d971d47f87 100644
--- a/tools/bootconfig/main.c
+++ b/tools/bootconfig/main.c
@@ -140,6 +140,9 @@ static int load_xbc_fd(int fd, char **buf, int size)
 {
 	int ret;
 
+	if (size < 0 || size > XBC_DATA_MAX)
+		return -EINVAL;
+
 	*buf = malloc(size + 1);
 	if (!*buf)
 		return -ENOMEM;
@@ -168,6 +171,13 @@ static int load_xbc_file(const char *path, char **buf)
 		return ret;
 	}
 
+	if (stat.st_size > XBC_DATA_MAX) {
+		pr_err("%s size is too big\n", path);
+		ret = -E2BIG;
+		close(fd);
+		return ret;
+	}
+
 	ret = load_xbc_fd(fd, buf, stat.st_size);
 
 	close(fd);
@@ -218,7 +228,8 @@ static int load_xbc_from_initrd(int fd, char **buf)
 	csum = le32toh(csum);
 
 	/* Wrong size error  */
-	if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
+	if (size > XBC_DATA_MAX ||
+	    size > stat.st_size - BOOTCONFIG_FOOTER_SIZE) {
 		pr_err("bootconfig size is too big\n");
 		return -E2BIG;
 	}


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check
  2026-09-10  1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
  2026-09-10  1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
@ 2026-09-10  1:59 ` Masami Hiramatsu (Google)
  1 sibling, 0 replies; 3+ messages in thread
From: Masami Hiramatsu (Google) @ 2026-09-10  1:59 UTC (permalink / raw)
  To: Masami Hiramatsu, Andrew Morton, Breno Leitao, Christian Brauner,
	Thomas Gleixner, Ryan Roberts, Thomas Weißschuh,
	Douglas Anderson, Huacai Chen
  Cc: Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon

From: Masami Hiramatsu (Google) <mhiramat@kernel.org>

Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd
with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer
arithmetic:

    data = ((void *)hdr) - size;

to wrap around on 32-bit systems (or when pointer subtraction overflows).
Because data wraps around, the subsequent bounds check:

    if ((unsigned long)data < initrd_start)

evaluates to false, bypassing the check. The kernel then calls
xbc_calc_checksum(data, size), which attempts to read 4GB of memory,
hitting unmapped pages and triggering a fatal kernel page fault during
early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an
unbounded 32-bit size can similarly bypass the initrd_start check.

Fix this by:
1. Ensuring the initrd is at least large enough to contain the bootconfig
   footer and verifying hdr is within the initrd bounds.
2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
   the available space between initrd_start and hdr before performing
   pointer subtraction.

Fixes: de462e5f1071 ("bootconfig: Fix to remove bootconfig data from initrd while boot")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@smtp.kernel.org/
Assisted-by: Antigravity:gemini-3.8-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
---
 init/main.c |   14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

diff --git a/init/main.c b/init/main.c
index 2613d3f9b3ce..60c27d5f2bce 100644
--- a/init/main.c
+++ b/init/main.c
@@ -277,7 +277,8 @@ static void * __init get_boot_config_from_initrd(size_t *_size)
 	u8 *hdr;
 	int i;
 
-	if (!initrd_end)
+	if (!initrd_end || initrd_end < initrd_start ||
+	    initrd_end - initrd_start < BOOTCONFIG_MAGIC_LEN + 8)
 		return NULL;
 
 	data = (char *)initrd_end - BOOTCONFIG_MAGIC_LEN;
@@ -294,16 +295,21 @@ static void * __init get_boot_config_from_initrd(size_t *_size)
 
 found:
 	hdr = (u8 *)(data - 8);
+	if ((unsigned long)hdr < initrd_start)
+		return NULL;
+
 	size = get_unaligned_le32(hdr);
 	csum = get_unaligned_le32(hdr + 4);
 
-	data = ((void *)hdr) - size;
-	if ((unsigned long)data < initrd_start) {
-		pr_err("bootconfig size %d is greater than initrd size %ld\n",
+	if (size > XBC_DATA_MAX ||
+	    size > ((unsigned long)hdr - initrd_start)) {
+		pr_err("bootconfig size %u is greater than initrd size %lu\n",
 			size, initrd_end - initrd_start);
 		return NULL;
 	}
 
+	data = ((void *)hdr) - size;
+
 	if (xbc_calc_checksum(data, size) != csum) {
 		pr_err("bootconfig checksum failed\n");
 		return NULL;


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-10  1:59 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-10  1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
2026-09-10  1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
2026-09-10  1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®