From nobody Tue Sep 29 04:12:24 2026 Received: from smtp-relay-internal-0.canonical.com (smtp-relay-internal-0.canonical.com [185.125.188.122]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 021211DDC1B for ; Wed, 12 Aug 2026 14:18:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.125.188.122 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786544341; cv=none; b=irZoSh5FaxoO3fvh0D8pkqJ0uWfIeNijwkaKt9rAicbu3dq3Eed319KvXR8Ak/eAIBM14vYiIzihQpR4h3Sr+0zBjQoMXSvhoBcfSZPfpHIJaxMonmEG3sQsCx6+RSzQk4IjInd+fljr7+WQF5K8DQMT+81fK5XbDqfsRhwj1Bs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786544341; c=relaxed/simple; bh=cO4Pj9HJvXCrtKDWlg8BCMRgxRtBdS4Ni/h9SSOUwWU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=GN6WYuHdYZcImhrHTwqw4vlJwMeBFfM26rs7r74PPbnoTCLFXMrf4kD/70GCa+RVQUbjFvdbFUH961ijaZv1Mln1Umb+MUg7ywDjQH41F+QtUBJQEXL1nP4SCU6aM9/YtqljKTgVNuPu6EuxME3vOBitJ6rYpBNpB9eXDubpHZQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com; spf=pass smtp.mailfrom=canonical.com; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b=CSkouF3c; arc=none smtp.client-ip=185.125.188.122 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=canonical.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b="CSkouF3c" Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-0.canonical.com (Postfix) with ESMTPS id F0E273FC26 for ; Wed, 12 Aug 2026 14:18:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20251003; t=1786544334; bh=ziTqEENmhcZwJoI7CW+xasRu/XWt1NvwONmfzBdAPeA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=CSkouF3cwL8xsterUNLCTdLVv69S3SY6bCVZ40y/hbDr8GTsqMinjtXkf5rrSxENs kKnEbFxgq4LCUaam2s5qvPO9Dx63n39wDHFB0LqBYk6xMTLBfgnx3hZV/ahDnXZc+b WY5jXtnsSKd//pJJpnqDeQGMFHDtQx4rMoT48pL3dmkXA16u7RJxBbdahhfwoeeeH9 SEk5Yggq/7wtpW4t9gYJJaVr0vAAVg1ZRBWLUUyJh1YnqIoS9ijUfNG4xlgdWhvxPz CA//8n0ORpSL2C3k+ivuXruVKQ9yVCOKSCdQNQjU0HgRAqkoJVS0eAmvoBUKUSEAf/ tZd7/wFX6afpo2mY4FpITDEHZI4+05BW9Z6l19r/Q6FiKHov7XYbwQpqWCahR8kRoA BFbwLDmlEcG5SzPpQjMddQaDV54l0v7jtuX6o/QxcXnVvrWRHFRhy+QVizyqpdNSbe hxvCfUElJlTk3UkzF4/ZyIg+E8739kp6BXUovyfEsrc4ey5QaYhRE/KmiLkQbdzS12 R74Dx+6ke7hZhfaixIYqEVOwZJxWNljS7kRenknM+z5dybqf5exkINJSaUjzZTnyun hmdyHA0cJlpd8iIW5zBdmNvdjwTn99hBPSnLjhPPQ6FVuFMnmHW4V+YKXNGaDd3r+d lHcAf1lwZFnlh9qiF75mbFmA= Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-4954dcd6131so9663035e9.3 for ; Wed, 12 Aug 2026 07:18:54 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786544334; x=1787149134; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ziTqEENmhcZwJoI7CW+xasRu/XWt1NvwONmfzBdAPeA=; b=khRPQ1lxF2X6nMRMdDuCGevKV2SWxUkuqE4FM0RvHkwErXmwAi8PMz2KZPapQnKZWV 13DLOBzI2ADULI66WySYFyleFQNlnZdEXEb2cNUMxPqTFBJtbRR676hx3X36UuCWljGZ nDN2KvFiBtXIi53yJRYU2uIAQEdy6Dj6UN/Iz57uh5i/F4gYVkXEbslNYjOsZkIs+/lc IgmG2auC9iGjYzJaABg0vXznJujoe3PGzKjxVHyDlfGL1UDi/Q0PYuldSXV+qr67IIwy S7o9ZxlQIJxOnMAgKWZVOvbMCDN62+YNdIu3qrA9g0paptZD+PzLD1Xhdc1DycL15Xdp YYCw== X-Forwarded-Encrypted: i=1; AHgh+RrDToKCH4KS5IKEWzZMF7TEOUwfCQjuGgmEmYZZVqedIcq2AlS9GuDoigl9sbMJo2nod/JWCg+waiJm2jw=@vger.kernel.org X-Gm-Message-State: AOJu0YwD7A51X0XFtxpdhxtr509lq0i7thszwMLKBcWqI57vcbPXIGib fIwwP/fdY3mWvT4EqLoCgPpmzwub2h3ZuiTm4A1E7RJQT1Syak6VQaNWGjGBCT3ok+2+1QLhFa+ p1JeOMy62bkNI8hQFghxq1Cw7RLcbnRwzgj7wq2Z3lSWWTbUczz2SqZLe3v5tDfN5E7KU1Pzmbg 4tBdfCFQ== X-Gm-Gg: AR+sD10oUvjXKmGoHv3rOI44QjULjjOt2XYwOF/effwhculQFStCaTOsOj2fkAWvZPr KCzuB+cIspL3/oA3tedJo3A4Fa983X711CFBfKmpdYk8Aa4c0I1nq+xnNh8RHXbpJ/eDTsii4Fu Hlri4Xpgkhp3W8v+pDdd2bfFBSjsMT0AK5brStgQYp6icBhdHCES/jp8srw+Y0WvGW9+QZ+7NlX 4UsO8RKDAkcGUKfgGl+ZsE3YZoidzQuPcdHjsRz9GPMUHMM1u0ehucm6oUmJelMGuGhQTXOy1cb YfQAogT0k1akUlNZSOQT2WTHdjdxard4ykh8/I3T1R9+ODtCUQ+5yz+VVQb8hrY8QJnhKbV52Rs egxl5ZEReXkFPIE9scOLFDGKqT7UQF57GXGF332yf65oiIkAnGMGrYYLZJQBdAyMtR84m48pr7z fbPqbPEB793X7UtWSlS5krWcre X-Received: by 2002:a05:600c:35c1:b0:499:811b:dfed with SMTP id 5b1f17b1804b1-499811be003mr10736515e9.5.1786544334126; Wed, 12 Aug 2026 07:18:54 -0700 (PDT) X-Received: by 2002:a05:600c:35c1:b0:499:811b:dfed with SMTP id 5b1f17b1804b1-499811be003mr10735465e9.5.1786544333585; Wed, 12 Aug 2026 07:18:53 -0700 (PDT) Received: from t-14 (2a01cb00088323003ba1cc9bdc9c322c.ipv6.abo.wanadoo.fr. [2a01:cb00:883:2300:3ba1:cc9b:dc9c:322c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4997c8fa1c7sm71800405e9.0.2026.08.12.07.18.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 07:18:53 -0700 (PDT) From: Fabrice Derepas To: Mimi Zohar , Roberto Sassu , Dmitry Kasatkin Cc: Fabrice Derepas , Eric Snowberg , Paul Moore , James Morris , "Serge E. Hallyn" , linux-integrity@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH] ima: reject a kexec buffer whose declared size exceeds the buffer Date: Wed, 12 Aug 2026 16:18:40 +0200 Message-ID: <20260812141842.2319635-1-fabrice.derepas@canonical.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ima_restore_measurement_list() parses the measurement list persisted across kexec. It computes the parse end directly from the blob: bufendp =3D buf + khdr->buffer_size; khdr->buffer_size is a u64 read straight from the persisted buffer. The only length checks in the function are size >=3D sizeof(*khdr), version =3D= =3D 1 and count -- none relates buffer_size to size, the actual buffer size the caller (ima_load_kexec_buffer()) obtained from the ima-kexec-buffer region. ima_parse_buf() bounds every field read to bufendp, so a blob whose internal buffer_size exceeds the real size makes the parse loop read past the end of the buffer (CWE-125). The buffer's memory range is validated against addressable RAM by commit cbf9c4b9617b ("of: check previous kernel's ima-kexec-buffer against memory bounds") and commit c5489d04337b ("x86/kexec: add a sanity check on previous kernel's ima kexec buffer"), but the blob's own declared size is never clamped to it. Reject a buffer_size larger than size before the loop. This is on the boot-time kexec-restore path (__init) and the buffer comes from the previous kernel, so triggering it requires control of the persisted buffer; it is an out-of-bounds read only. Fixes: 94c3aac567a9 ("ima: on soft reboot, restore the measurement list") Assisted-by: copilot-cli:claude-opus-4-6 frama-c Signed-off-by: Fabrice Derepas --- Tested under KASAN (CONFIG_KASAN_GENERIC, x86-64) with a KUnit case that ca= lls ima_restore_measurement_list() on a 24-byte buffer whose header declares buffer_size =3D 0x1000. On an unpatched kernel this takes a slab-out-of-bo= unds read of size 4 in ima_parse_buf() from ima_restore_measurement_list(); with this patch the buffer is rejected and the case passes with no KASAN report. The test is not included here (there is no upstream IMA KUnit suite yet); I= 'm happy to submit it separately if useful. security/integrity/ima/ima_template.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/security/integrity/ima/ima_template.c b/security/integrity/ima= /ima_template.c index 7034573..2467cae 100644 --- a/security/integrity/ima/ima_template.c +++ b/security/integrity/ima/ima_template.c @@ -450,6 +450,11 @@ int ima_restore_measurement_list(loff_t size, void *bu= f) return -EINVAL; } =20 + if (khdr->buffer_size > size) { + pr_err("attempting to restore a corrupted measurement list"); + return -EINVAL; + } + bitmap_zero(hdr_mask, HDR__LAST); bitmap_set(hdr_mask, HDR_PCR, 1); bitmap_set(hdr_mask, HDR_DIGEST, 1); base-commit: f5bbbfec59b4e2fb7520a91de3df8a6174325d6a --=20 2.53.0