mirror of
https://git.yoctoproject.org/poky
synced 2026-07-22 10:17:48 +02:00
The previous CVE-2023-30630_1.patch picked only the patch
"dmidecode: Write the whole dump file at once" d8cfbc808f.
But there was a refactoring which does not allow to cherry-pick it fast
forward. Resolving this conflict was not correctly done. The patch was:
+ u32 len;
+ u8 *table;
...
- if (!(opt.flags & FLAG_QUIET))
- pr_comment("Writing %d bytes to %s.", crafted[0x05],
- opt.dumpfile);
- write_dump(0, crafted[0x05], crafted, opt.dumpfile, 1);
+ dmi_table_dump(crafted, crafted[0x05], table, len);
It looks like the variables len and table have been added without
initialization.
Now this problem is solved by applying the previous refactoring as
well. Patch 1 gets replaced by Patch 1a and Patch 1b. Patch 2..4 are
rebased without changes.
This is basically the same patch as in kirkstone:
ea069a94a2 dmidecode: fixup for CVE-2023-30630
(From OE-Core rev: 0bc69dc078c39381a39789d3c5fff673d7da994c)
Signed-off-by: Sean Nyekjaer <sean@geanix.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
71 lines
2.2 KiB
Diff
71 lines
2.2 KiB
Diff
From c76ddda0ba0aa99a55945e3290095c2ec493c892 Mon Sep 17 00:00:00 2001
|
|
From: Jean Delvare <jdelvare@suse.de>
|
|
Date: Tue, 27 Jun 2023 10:25:50 +0000
|
|
Subject: [PATCH] Consistently use read_file() when reading from a dump file
|
|
|
|
Use read_file() instead of mem_chunk() to read the entry point from a
|
|
dump file. This is faster, and consistent with how we then read the
|
|
actual DMI table from that dump file.
|
|
|
|
This made no functional difference so far, which is why it went
|
|
unnoticed for years. But now that a file type check was added to the
|
|
mem_chunk() function, we must stop using it to read from regular
|
|
files.
|
|
|
|
This will again allow root to use the --from-dump option.
|
|
|
|
Signed-off-by: Jean Delvare <jdelvare@suse.de>
|
|
Tested-by: Jerry Hoemann <jerry.hoemann@hpe.com>
|
|
|
|
CVE: CVE-2023-30630
|
|
|
|
Upstream-Status: Backport [https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=c76ddda0ba0aa99a55945e3290095c2ec493c892]
|
|
|
|
Signed-off-by: Yogita Urade <yogita.urade@windriver.com>
|
|
---
|
|
dmidecode.c | 11 +++++++++--
|
|
1 file changed, 9 insertions(+), 2 deletions(-)
|
|
|
|
diff --git a/dmidecode.c b/dmidecode.c
|
|
index d339577..1ecdf85 100644
|
|
--- a/dmidecode.c
|
|
+++ b/dmidecode.c
|
|
@@ -6031,17 +6031,25 @@ int main(int argc, char * const argv[])
|
|
pr_comment("dmidecode %s", VERSION);
|
|
|
|
/* Read from dump if so instructed */
|
|
+ size = 0x20;
|
|
if (opt.flags & FLAG_FROM_DUMP)
|
|
{
|
|
if (!(opt.flags & FLAG_QUIET))
|
|
pr_info("Reading SMBIOS/DMI data from file %s.",
|
|
opt.dumpfile);
|
|
- if ((buf = mem_chunk(0, 0x20, opt.dumpfile)) == NULL)
|
|
+ if ((buf = read_file(0, &size, opt.dumpfile)) == NULL)
|
|
{
|
|
ret = 1;
|
|
goto exit_free;
|
|
}
|
|
|
|
+ /* Truncated entry point can't be processed */
|
|
+ if (size < 0x20)
|
|
+ {
|
|
+ ret = 1;
|
|
+ goto done;
|
|
+ }
|
|
+
|
|
if (memcmp(buf, "_SM3_", 5) == 0)
|
|
{
|
|
if (smbios3_decode(buf, opt.dumpfile, 0))
|
|
@@ -6065,7 +6073,6 @@ int main(int argc, char * const argv[])
|
|
* contain one of several types of entry points, so read enough for
|
|
* the largest one, then determine what type it contains.
|
|
*/
|
|
- size = 0x20;
|
|
if (!(opt.flags & FLAG_NO_SYSFS)
|
|
&& (buf = read_file(0, &size, SYS_ENTRY_FILE)) != NULL)
|
|
{
|
|
--
|
|
2.42.0
|
|
|