Re: [PATCH v4 1/2] tools/bootconfig: Fix integer overflow and truncation in size checks

From: Sang-Heon Jeon

Date: Thu Sep 10 2026 - 12:24:32 EST


On Fri, Sep 11, 2026 at 12:15 AM Masami Hiramatsu (Google)
<mhiramat@xxxxxxxxxx> wrote:
>
> From: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
>
> Sashiko reported that on 32-bit systems, if an attacker crafts size in
> the bootconfig footer such that adding BOOTCONFIG_FOOTER_SIZE wraps around
> (for instance, if size is 0xFFFFFFFF), the size check in
> load_xbc_from_initrd() can be bypassed:
>
> if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
> pr_err("bootconfig size is too big\n");
> return -E2BIG;
> }
>
> Furthermore, on 64-bit systems with an initrd > 4.29 GB, comparing a
> corrupted 32-bit size (e.g. 0xFFFFFFFF) against
> stat.st_size - BOOTCONFIG_FOOTER_SIZE can also bypass the check if
> size is not bounded. Similarly, load_xbc_file() passes 64-bit stat.st_size
> directly into the 32-bit int size parameter of load_xbc_fd(), truncating
> large standalone files (>= 2GB).
>
> In both cases, passing 0xFFFFFFFF to load_xbc_fd() truncates to -1,
> resulting in malloc(0), an integer overflow in read(), and an
> out-of-bounds null-byte write.
>
> Fix this by:
> 1. Rejecting size > XBC_DATA_MAX or
> size > stat.st_size - BOOTCONFIG_FOOTER_SIZE in load_xbc_from_initrd().
> 2. Rejecting stat.st_size > XBC_DATA_MAX in load_xbc_file() before passing
> it to load_xbc_fd().
> 3. Checking size < 0 || size > XBC_DATA_MAX defensively in load_xbc_fd().
>
> Fixes: 950313ebf79c ("tools: bootconfig: Add bootconfig command")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Closes: https://lore.kernel.org/all/20260909161113.16C691F00A3A@xxxxxxxxxxxxxxx/
> Closes: https://lore.kernel.org/all/20260910010137.EE0431F000FF@xxxxxxxxxxxxxxx/
> Assisted-by: Antigravity:gemini-3.8-flash
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@xxxxxxxxxx>
> ---
> Changes in v3:
> - Reject size > XBC_DATA_MAX and
> size > stat.st_size - BOOTCONFIG_FOOTER_SIZE in load_xbc_from_initrd()
> to prevent bypass on initrd > 4.29 GB.
> - Check stat.st_size > XBC_DATA_MAX in load_xbc_file() to prevent
> truncation on large standalone files.
> - Check size < 0 || size > XBC_DATA_MAX defensively in load_xbc_fd().
> Changes in v2:
> - Add Cc: stable.
> - Also reject if "size > XBC_DATA_MAX", that is obviously wrong.
> ---
> tools/bootconfig/main.c | 13 ++++++++++++-
> 1 file changed, 12 insertions(+), 1 deletion(-)
>
> diff --git a/tools/bootconfig/main.c b/tools/bootconfig/main.c
> index 7dc9fff9b637..17d971d47f87 100644
> --- a/tools/bootconfig/main.c
> +++ b/tools/bootconfig/main.c
> @@ -140,6 +140,9 @@ static int load_xbc_fd(int fd, char **buf, int size)
> {
> int ret;
>
> + if (size < 0 || size > XBC_DATA_MAX)
> + return -EINVAL;
> +
> *buf = malloc(size + 1);
> if (!*buf)
> return -ENOMEM;
> @@ -168,6 +171,13 @@ static int load_xbc_file(const char *path, char **buf)
> return ret;
> }
>
> + if (stat.st_size > XBC_DATA_MAX) {
> + pr_err("%s size is too big\n", path);
> + ret = -E2BIG;
> + close(fd);
> + return ret;
> + }
> +
> ret = load_xbc_fd(fd, buf, stat.st_size);
>
> close(fd);
> @@ -218,7 +228,8 @@ static int load_xbc_from_initrd(int fd, char **buf)
> csum = le32toh(csum);
>
> /* Wrong size error */
> - if (stat.st_size < size + BOOTCONFIG_FOOTER_SIZE) {
> + if (size > XBC_DATA_MAX ||
> + size > stat.st_size - BOOTCONFIG_FOOTER_SIZE) {
> pr_err("bootconfig size is too big\n");
> return -E2BIG;
> }
>

Reviewed-by: Sang-Heon Jeon <ekffu200098@xxxxxxxxx>