* [PATCH v3 0/2] bootconfig: Fix integer overflow problems
@ 2026-09-10 1:59 Masami Hiramatsu (Google)
2026-09-10 1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
2026-09-10 1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
0 siblings, 2 replies; 4+ messages in thread
From: Masami Hiramatsu (Google) @ 2026-09-10 1:59 UTC (permalink / raw)
To: Masami Hiramatsu, Andrew Morton, Breno Leitao, Christian Brauner,
Thomas Gleixner, Ryan Roberts, Thomas Weißschuh,
Douglas Anderson, Huacai Chen
Cc: Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon
Hi,
Here are patches to fix bootconfig size overflow issue. If there is a wrong
bootconfig size is recorded, it can bypass the size check in the tool and the
kernel.
The previous version only fixes tools, but Sashiko found the same issue in
the kernel. So this version add that fix.
Here is the previous version.
https://lore.kernel.org/all/178900114498.187028.9558747732041210116.stgit@devnote2/
Thank you,
---
Masami Hiramatsu (Google) (2):
tools/bootconfig: Fix integer overflow and truncation in size checks
bootconfig: Fix integer overflow in initrd size check
init/main.c | 14 ++++++++++----
tools/bootconfig/main.c | 13 ++++++++++++-
2 files changed, 22 insertions(+), 5 deletions(-)
--
Masami Hiramatsu (Google) <mhiramat@kernel.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks
2026-09-10 1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
@ 2026-09-10 1:59 ` Masami Hiramatsu (Google)
2026-09-10 1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
1 sibling, 0 replies; 4+ messages in thread
From: Masami Hiramatsu (Google) @ 2026-09-10 1:59 UTC (permalink / raw)
To: Masami Hiramatsu, Andrew Morton, Breno Leitao, Christian Brauner,
Thomas Gleixner, Ryan Roberts, Thomas Weißschuh,
Douglas Anderson, Huacai Chen
Cc: Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Sashiko reported that on 32-bit systems, if an attacker crafts size in
the bootconfig footer such that adding BOOTCONFIG_FOOTER_SIZE wraps around
(for instance, if size is 0xFFFFFFFF), the size check in
load_xbc_from_initrd() can be bypassed:
if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
pr_err("bootconfig size is too big\n");
return -E2BIG;
}
Furthermore, on 64-bit systems with an initrd > 4.29 GB, comparing a
corrupted 32-bit size (e.g. 0xFFFFFFFF) against
stat.st_size - BOOTCONFIG_FOOTER_SIZE can also bypass the check if
size is not bounded. Similarly, load_xbc_file() passes 64-bit stat.st_size
directly into the 32-bit int size parameter of load_xbc_fd(), truncating
large standalone files (>= 2GB).
In both cases, passing 0xFFFFFFFF to load_xbc_fd() truncates to -1,
resulting in malloc(0), an integer overflow in read(), and an
out-of-bounds null-byte write.
Fix this by:
1. Rejecting size > XBC_DATA_MAX or
size > stat.st_size - BOOTCONFIG_FOOTER_SIZE in load_xbc_from_initrd().
2. Rejecting stat.st_size > XBC_DATA_MAX in load_xbc_file() before passing
it to load_xbc_fd().
3. Checking size < 0 || size > XBC_DATA_MAX defensively in load_xbc_fd().
Fixes: 950313ebf79c ("tools: bootconfig: Add bootconfig command")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260909161113.16C691F00A3A@smtp.kernel.org/
Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@smtp.kernel.org/
Assisted-by: Antigravity:gemini-3.8-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
---
Changes in v3:
- Reject size > XBC_DATA_MAX and
size > stat.st_size - BOOTCONFIG_FOOTER_SIZE in load_xbc_from_initrd()
to prevent bypass on initrd > 4.29 GB.
- Check stat.st_size > XBC_DATA_MAX in load_xbc_file() to prevent
truncation on large standalone files.
- Check size < 0 || size > XBC_DATA_MAX defensively in load_xbc_fd().
Changes in v2:
- Add Cc: stable.
- Also reject if "size > XBC_DATA_MAX", that is obviously wrong.
---
tools/bootconfig/main.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/tools/bootconfig/main.c b/tools/bootconfig/main.c
index 7dc9fff9b637..17d971d47f87 100644
--- a/tools/bootconfig/main.c
+++ b/tools/bootconfig/main.c
@@ -140,6 +140,9 @@ static int load_xbc_fd(int fd, char **buf, int size)
{
int ret;
+ if (size < 0 || size > XBC_DATA_MAX)
+ return -EINVAL;
+
*buf = malloc(size + 1);
if (!*buf)
return -ENOMEM;
@@ -168,6 +171,13 @@ static int load_xbc_file(const char *path, char **buf)
return ret;
}
+ if (stat.st_size > XBC_DATA_MAX) {
+ pr_err("%s size is too big\n", path);
+ ret = -E2BIG;
+ close(fd);
+ return ret;
+ }
+
ret = load_xbc_fd(fd, buf, stat.st_size);
close(fd);
@@ -218,7 +228,8 @@ static int load_xbc_from_initrd(int fd, char **buf)
csum = le32toh(csum);
/* Wrong size error */
- if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
+ if (size > XBC_DATA_MAX ||
+ size > stat.st_size - BOOTCONFIG_FOOTER_SIZE) {
pr_err("bootconfig size is too big\n");
return -E2BIG;
}
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check
2026-09-10 1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
2026-09-10 1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
@ 2026-09-10 1:59 ` Masami Hiramatsu (Google)
2026-09-10 10:05 ` Breno Leitao
1 sibling, 1 reply; 4+ messages in thread
From: Masami Hiramatsu (Google) @ 2026-09-10 1:59 UTC (permalink / raw)
To: Masami Hiramatsu, Andrew Morton, Breno Leitao, Christian Brauner,
Thomas Gleixner, Ryan Roberts, Thomas Weißschuh,
Douglas Anderson, Huacai Chen
Cc: Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon
From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd
with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer
arithmetic:
data = ((void *)hdr) - size;
to wrap around on 32-bit systems (or when pointer subtraction overflows).
Because data wraps around, the subsequent bounds check:
if ((unsigned long)data < initrd_start)
evaluates to false, bypassing the check. The kernel then calls
xbc_calc_checksum(data, size), which attempts to read 4GB of memory,
hitting unmapped pages and triggering a fatal kernel page fault during
early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an
unbounded 32-bit size can similarly bypass the initrd_start check.
Fix this by:
1. Ensuring the initrd is at least large enough to contain the bootconfig
footer and verifying hdr is within the initrd bounds.
2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
the available space between initrd_start and hdr before performing
pointer subtraction.
Fixes: de462e5f1071 ("bootconfig: Fix to remove bootconfig data from initrd while boot")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@smtp.kernel.org/
Assisted-by: Antigravity:gemini-3.8-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
---
init/main.c | 14 ++++++++++----
1 file changed, 10 insertions(+), 4 deletions(-)
diff --git a/init/main.c b/init/main.c
index 2613d3f9b3ce..60c27d5f2bce 100644
--- a/init/main.c
+++ b/init/main.c
@@ -277,7 +277,8 @@ static void * __init get_boot_config_from_initrd(size_t *_size)
u8 *hdr;
int i;
- if (!initrd_end)
+ if (!initrd_end || initrd_end < initrd_start ||
+ initrd_end - initrd_start < BOOTCONFIG_MAGIC_LEN + 8)
return NULL;
data = (char *)initrd_end - BOOTCONFIG_MAGIC_LEN;
@@ -294,16 +295,21 @@ static void * __init get_boot_config_from_initrd(size_t *_size)
found:
hdr = (u8 *)(data - 8);
+ if ((unsigned long)hdr < initrd_start)
+ return NULL;
+
size = get_unaligned_le32(hdr);
csum = get_unaligned_le32(hdr + 4);
- data = ((void *)hdr) - size;
- if ((unsigned long)data < initrd_start) {
- pr_err("bootconfig size %d is greater than initrd size %ld\n",
+ if (size > XBC_DATA_MAX ||
+ size > ((unsigned long)hdr - initrd_start)) {
+ pr_err("bootconfig size %u is greater than initrd size %lu\n",
size, initrd_end - initrd_start);
return NULL;
}
+ data = ((void *)hdr) - size;
+
if (xbc_calc_checksum(data, size) != csum) {
pr_err("bootconfig checksum failed\n");
return NULL;
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check
2026-09-10 1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
@ 2026-09-10 10:05 ` Breno Leitao
0 siblings, 0 replies; 4+ messages in thread
From: Breno Leitao @ 2026-09-10 10:05 UTC (permalink / raw)
To: Masami Hiramatsu (Google)
Cc: Andrew Morton, Christian Brauner, Thomas Gleixner, Ryan Roberts,
Thomas Weißschuh, Douglas Anderson, Huacai Chen,
Mark Rutland, linux-kernel, linux-trace-kernel, Sang-Heon Jeon
On Thu, Sep 10, 2026 at 10:59:35AM +0900, Masami Hiramatsu (Google) wrote:
> From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
>
> Sashiko reported that in get_boot_config_from_initrd(), a crafted initrd
> with a huge bootconfig size (such as 0xFFFFFFFF) can cause the pointer
> arithmetic:
>
> data = ((void *)hdr) - size;
>
> to wrap around on 32-bit systems (or when pointer subtraction overflows).
> Because data wraps around, the subsequent bounds check:
>
> if ((unsigned long)data < initrd_start)
>
> evaluates to false, bypassing the check. The kernel then calls
> xbc_calc_checksum(data, size), which attempts to read 4GB of memory,
> hitting unmapped pages and triggering a fatal kernel page fault during
> early boot. Furthermore, on 64-bit systems with an initrd > 4.29 GB, an
> unbounded 32-bit size can similarly bypass the initrd_start check.
>
> Fix this by:
> 1. Ensuring the initrd is at least large enough to contain the bootconfig
> footer and verifying hdr is within the initrd bounds.
> 2. Checking that size does not exceed XBC_DATA_MAX and does not exceed
> the available space between initrd_start and hdr before performing
> pointer subtraction.
>
> Fixes: de462e5f1071 ("bootconfig: Fix to remove bootconfig data from initrd while boot")
> Cc: stable@vger.kernel.org
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@smtp.kernel.org/
> Assisted-by: Antigravity:gemini-3.8-flash
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Breno Leitao <leitao@debian.org>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-10 10:05 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-10 1:59 [PATCH v3 0/2] bootconfig: Fix integer overflow problems Masami Hiramatsu (Google)
2026-09-10 1:59 ` [PATCH v3 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks Masami Hiramatsu (Google)
2026-09-10 1:59 ` [PATCH v3 2/2] bootconfig: Fix integer overflow in initrd size check Masami Hiramatsu (Google)
2026-09-10 10:05 ` Breno Leitao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®