В ядре Linux устранена следующая уязвимость:
платформа/x86: hp-bioscfg: исправлено чтение кучи OOB при записи пустого пароля
validate_password_input() вычисляет длину = strlen(buf), а затем
проверяет buf[length - 1] для удаления завершающей новой строки без проверки
эта длина сначала не равна нулю. Написание пустой строки (голого '\n')
для current_password или new_password дает длину == 0, и
buf[длина - 1] читает buf[-1], за один байт до выделения кучи
удерживая скопированный ввод. КАСАН подтверждает это прямо:
ОШИБКА: KASAN: плита выходит за пределы в store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]
Чтение размера 1 по адресу ffff88811bd8da9f с помощью задачи sh/13740.
...
store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg]
current_password_store+0x14/0x20 [hp_bioscfg]
...
Глючный адрес расположен в 23 байтах справа от
выделенная 8-байтовая область [ffff88811bd8da80, ffff88811bd8da88)
Воспроизводится идентично через new_password_store. Выполнение продолжается
после плохого чтения (байт мусора влияет только на то, является ли "длина"
уменьшается на единицу), поэтому запись завершается и возвращает успех; это
это чистая информация, прочитанная мимо буфера, а не сбой, но это
все равно выход за пределы доступа KASAN правильно помечает. Исправьте это, проверив buf[length - 1] только тогда, когда длина не равна нулю.
Показать оригинальное описание (EN)
In the Linux kernel, the following vulnerability has been resolved: platform/x86: hp-bioscfg: fix heap OOB read on empty password write validate_password_input() computes length = strlen(buf) and then checks buf[length - 1] to strip a trailing newline, without checking that length is nonzero first. Writing an empty string (a bare '\n') to current_password or new_password gives length == 0, and buf[length - 1] reads buf[-1], one byte before the heap allocation holding the copied input. KASAN confirms this directly: BUG: KASAN: slab-out-of-bounds in store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] Read of size 1 at addr ffff88811bd8da9f by task sh/13740 ... store_password_instance.constprop.0+0x223/0x2a0 [hp_bioscfg] current_password_store+0x14/0x20 [hp_bioscfg] ... The buggy address is located 23 bytes to the right of allocated 8-byte region [ffff88811bd8da80, ffff88811bd8da88) Reproduced identically via new_password_store. Execution continues past the bad read (the garbage byte only affects whether "length" is decremented by one), so the write completes and returns success; this is a pure information read past the buffer, not a crash, but it is still an out-of-bounds access KASAN correctly flags. Fix by only checking buf[length - 1] when length is nonzero.