From nobody Tue Sep 29 02:02:54 2026 Received: from smtp-relay-internal-1.canonical.com (smtp-relay-internal-1.canonical.com [185.125.188.123]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0451F2F8E93 for ; Thu, 13 Aug 2026 16:57:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=185.125.188.123 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786640247; cv=none; b=pWCLYzhkN7+2R4v0xANf9VqdkpbBGgdio7Vtx1Bp7pEFiAUsr3EJTjYlv22ovN6VnK1Rmt97OecRHo9RcbDhAgMXbMwn38JS2/oSAh53os9MwdxqfmAwAjnE3JoMSgebrlukr3ii0rvO2b7uq3mzS42RzAzec7yMvN4ZJX8hywI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786640247; c=relaxed/simple; bh=9RpAvBQAy/SAGsjLUsavkvhR2IXORLH2z64F8pxIE2U=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=BdwBqZ7d81u0Po+BPFFIw+G1MhW5pA5c9kqCCd0t5dF6PgXooTFOcuIq4ICKP4RqyZpXCx0m5kdN3jpe+BtnSKsX2QiLcg7SP5v1rskxYNsuzOyUit7Qug8wImS05Y1nInbqZXHNr/V7QeBOSK70CaAQMZrMMw1YErL3HzS1mvM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com; spf=pass smtp.mailfrom=canonical.com; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b=jdk0cchK; arc=none smtp.client-ip=185.125.188.123 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=canonical.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=canonical.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (4096-bit key) header.d=canonical.com header.i=@canonical.com header.b="jdk0cchK" Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by smtp-relay-internal-1.canonical.com (Postfix) with ESMTPS id BB7EF3F135 for ; Thu, 13 Aug 2026 16:57:15 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=canonical.com; s=20251003; t=1786640235; bh=v4gKNmrcl/ldyDb/KPnMDoGw2a6pO4iklkGUcioG2dw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=jdk0cchKFh0+3KTIUUoaEU594EzICF17vl9sq4C1ObaND1GDlbhwwjM/RiIyMuQ0d Lg4y+WS2fJrOsVQqmoqXmZdLYdwSfDTmBnauQgCnbt8WqPojH3N8HHg/InawgsDwlw 1cXUYYa4nvqiXa7eOz9wLfRMr3xXFoHkpqhybF8jpAaUznVDA+tDzLMuMLGRBNYzhI kXXfA9lsNP5AFB/Kjltt8DNHkM1NGAPNbjHSEFlTiqVWNDdt/qQraJDX2DW6Q1D5AM uAyPkfxMFkrV/NPH7+aOt1T/RbxOPhMriD2vypLzmHyTGGrSCmX7oRMYOXsUMHIYup hNBJBbEHMbr4lKBIVNwy4cPbSgquGI1r8BGy/HK3jNCjnDJbcBRkkrmFNgfogfl+CR tOewMDo5ENVyuw/iM8vop44syZzl+aJkE1Bf+lyU78+ZXJAtEGyZMSzxqg29WiST/6 nbV1DcwasQdiH8wcFOGZENhETKQgQdejZTe7K1FiTfza1W/TxxCxSeQQEEVy6dOAI5 Tz0KaTi/79r+vz0fFoAQ5AVa7OI16ORUjr6+TudbTIDlyS76kjLEupEHNNq7koo577 4jFUZ87o8GaoKzHjIiNir7DNHD+UloRfc9aYvHt6ZJSX/mtFcMMGjX5+ZHvUhOunGe rrnWlYOhfJcryRpuAbV7/tg0= Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-4954b1c6310so1122905e9.0 for ; Thu, 13 Aug 2026 09:57:15 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786640235; x=1787245035; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=v4gKNmrcl/ldyDb/KPnMDoGw2a6pO4iklkGUcioG2dw=; b=sbnmtqBEsAYyLq5mmReZk71e6Fpdd1ZvWeTqLZlnbnMRyFQVMg20gRr40sdVkjyaib im32r24IgJwvR4LEEhdRR76ehadZdrv664sAuonT/tIx+O2UHc5vJY6BL/UMID5nn7Iq 0rd2kEFipBYK1eOZCZdYJAd/RZAMP4HEg1F90Wac5eh9wot7+iuU38ocf7/cOWIVmziJ 6Vap3GRZ9gr3xCzoGCtt7j2i4yZgxB5ZnxlSPAUqcEIHgbhruNm5S0J/o0Kw6nMHTysD qglNlk1FmMdbI1zRdZVGzg8UEcGOpPFb2bx99wk3iWZlc9c9KL4+7bSdNQxF1tpRN4ZI nL6g== X-Forwarded-Encrypted: i=1; AHgh+RoCAQ9/J7kb7RjMg+5p3ugta8Dv1QTPHNZivimiRTaJEP/9rv+fzWoOdN1kNlqvyLQ1fAHZmISupRdJeUE=@vger.kernel.org X-Gm-Message-State: AOJu0Yz2WkaShWLpONOZEdPBhSvns6+tBL1SBRwote0Rx5oO917H+ZWF YCByM6wuGsV735lN1fMq9YNCLoMvNY6nEuORMrwkiwfFhbHAjodult/09zIVM5ZQeM0AyocPL3v nX9VwcJI++k67ORO2pM11QmtOlgCn73vvuNU/zkQTyULjcfnbwzy9QYQW2uZGoxvG/8QlFm6yn/ OC6TMw7A== X-Gm-Gg: AR+sD11q5O5yDNcIFUJhnX85bL+xG8WhUgO3IBiIR/nzWKE3A1R/79TPkZp+agcgs1n 0zxfQwDRGPsWjPEGnXCv8iyl2YgwS6zNKSySYGNeyAwByTHhjZm+Tu2PRhm78E6vniXHLDE1Bsu sK0kKycpTt9k2wSzzleJcY/9U43Fhk4dKYIA+ZfEsJhPJ78gr78VHJuUSEamDz56VMBqukA5sK7 1J0QrmT94dHw9Za+IzhZ3iY6OV3CDqSIShCh/5rysqOLLP0o9FZjS/KYVAttxZROrgD8HybzPG2 Xon0mATbDAtz7VEpXAD+YGJzX/aKcX+HEbwZjRB3PFtGnvermiCx6yll423KNbu+p/YnzzGCMxm YuMT5mt41iKDb2Fyti6OWYKAsgHTxAxRMW79BHOU9KYGrrI5cdF0+qflQFfoJGX31CvDkWhTqyV 8viGLJHKX3ka75CgmkQGEG+Kx9 X-Received: by 2002:a05:600c:1d19:b0:496:c379:b2a1 with SMTP id 5b1f17b1804b1-499821548efmr108289015e9.2.1786640235330; Thu, 13 Aug 2026 09:57:15 -0700 (PDT) X-Received: by 2002:a05:600c:1d19:b0:496:c379:b2a1 with SMTP id 5b1f17b1804b1-499821548efmr108288525e9.2.1786640235000; Thu, 13 Aug 2026 09:57:15 -0700 (PDT) Received: from t-14 (2a01cb00088323008940b17acf2a49f2.ipv6.abo.wanadoo.fr. [2a01:cb00:883:2300:8940:b17a:cf2a:49f2]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4815f2cc81csm574151f8f.34.2026.08.13.09.57.14 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 13 Aug 2026 09:57:14 -0700 (PDT) From: Fabrice Derepas To: David Howells , Lukas Wunner , Ignat Korchagin , Herbert Xu Cc: Fabrice Derepas , "David S. Miller" , keyrings@vger.kernel.org, linux-crypto@vger.kernel.org, kexec@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH] crypto: asymmetric_keys - fix OOB read in pefile_parse_binary Date: Thu, 13 Aug 2026 18:56:45 +0200 Message-ID: <20260813165654.36098-1-fabrice.derepas@canonical.com> X-Mailer: git-send-email 2.53.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" pefile_parse_binary() reads the size field of the certificate table's data-directory entry, which sits at fixed index 4 of the PE optional header's data directory: ctx->certs_size =3D ddir->certs.size; but nothing ensures index 4 is present. n_data_dirents (the untrusted NumberOfRvaAndSizes) is only upper-bounded against header_size and may be 0, and header_size need only satisfy cursor < header_size < datalen. A crafted PE with n_data_dirents =3D 0 and a tiny header_size therefore causes the ddir->certs.size read to land past the end of the image (CWE-125). The chkaddr() that bounds the certificate blob runs only after this read. verify_pefile_signature() is reached from kexec_file_load() (the lockdown/secure-boot enforced PE-image signature path), and the image is parsed before its signature is checked. The trigger needs CAP_SYS_BOOT and the access is out-of-bounds read only (no write). Require the certificate table's data-directory entry (index 4) to be present; the existing upper-bound check then keeps ddir->certs within [cursor, header_size). Fixes: 26d1164be37f ("pefile: Parse a PE binary to find a key and a signatu= re contained therein") Assisted-by: copilot-cli:claude-opus-4-6 frama-c Signed-off-by: Fabrice Derepas --- Reproduced under KASAN (CONFIG_KASAN_GENERIC, x86-64) with a KUnit case that builds a crafted PE (valid MZ/PE/PE32 magics, data_dirs =3D 0, header_size = just past the optional header) and calls verify_pefile_signature() with a NULL keyring -- the parse runs before any signature check. On an unpatched kerne= l: BUG: KASAN: slab-out-of-bounds in verify_pefile_signature+0x1d6/0x950 Read of size 4 ... in pefile_parse_binary() (inlined) With this patch the crafted image is rejected (-ELIBBAD) before the read and the case passes with no KASAN report. The test is not included here; happy = to submit it separately. crypto/asymmetric_keys/verify_pefile.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/crypto/asymmetric_keys/verify_pefile.c b/crypto/asymmetric_key= s/verify_pefile.c index cec99db..e7f8bdb 100644 --- a/crypto/asymmetric_keys/verify_pefile.c +++ b/crypto/asymmetric_keys/verify_pefile.c @@ -87,6 +87,10 @@ static int pefile_parse_binary(const void *pebuf, unsign= ed int pelen, if (ctx->n_data_dirents > (ctx->header_size - cursor) / sizeof(*dde)) return -ELIBBAD; =20 + /* The certificate table entry is at fixed index 4 of the data directory.= */ + if (ctx->n_data_dirents <=3D 4) + return -ELIBBAD; + ddir =3D pebuf + cursor; cursor +=3D sizeof(*dde) * ctx->n_data_dirents; =20 base-commit: 3d6d817622b0a9721e3cc404df3469171582be13 --=20 2.53.0