1*4882a593SmuzhiyunFrom 5f5eb7ca8e971227e95745abe541df3e1509360e Mon Sep 17 00:00:00 2001 2*4882a593SmuzhiyunFrom: Darren Kenny <darren.kenny@oracle.com> 3*4882a593SmuzhiyunDate: Fri, 4 Dec 2020 15:39:00 +0000 4*4882a593SmuzhiyunSubject: [PATCH] video/readers/jpeg: Test for an invalid next marker reference 5*4882a593Smuzhiyun from a jpeg file 6*4882a593Smuzhiyun 7*4882a593SmuzhiyunWhile it may never happen, and potentially could be caught at the end of 8*4882a593Smuzhiyunthe function, it is worth checking up front for a bad reference to the 9*4882a593Smuzhiyunnext marker just in case of a maliciously crafted file being provided. 10*4882a593Smuzhiyun 11*4882a593SmuzhiyunFixes: CID 73694 12*4882a593Smuzhiyun 13*4882a593SmuzhiyunSigned-off-by: Darren Kenny <darren.kenny@oracle.com> 14*4882a593SmuzhiyunReviewed-by: Daniel Kiper <daniel.kiper@oracle.com> 15*4882a593SmuzhiyunSigned-off-by: Stefan Sørensen <stefan.sorensen@spectralink.com> 16*4882a593Smuzhiyun--- 17*4882a593Smuzhiyun grub-core/video/readers/jpeg.c | 6 ++++++ 18*4882a593Smuzhiyun 1 file changed, 6 insertions(+) 19*4882a593Smuzhiyun 20*4882a593Smuzhiyundiff --git a/grub-core/video/readers/jpeg.c b/grub-core/video/readers/jpeg.c 21*4882a593Smuzhiyunindex 31359a4..0b6ce3c 100644 22*4882a593Smuzhiyun--- a/grub-core/video/readers/jpeg.c 23*4882a593Smuzhiyun+++ b/grub-core/video/readers/jpeg.c 24*4882a593Smuzhiyun@@ -253,6 +253,12 @@ grub_jpeg_decode_quan_table (struct grub_jpeg_data *data) 25*4882a593Smuzhiyun next_marker = data->file->offset; 26*4882a593Smuzhiyun next_marker += grub_jpeg_get_word (data); 27*4882a593Smuzhiyun 28*4882a593Smuzhiyun+ if (next_marker > data->file->size) 29*4882a593Smuzhiyun+ { 30*4882a593Smuzhiyun+ /* Should never be set beyond the size of the file. */ 31*4882a593Smuzhiyun+ return grub_error (GRUB_ERR_BAD_FILE_TYPE, "jpeg: invalid next reference"); 32*4882a593Smuzhiyun+ } 33*4882a593Smuzhiyun+ 34*4882a593Smuzhiyun while (data->file->offset + sizeof (data->quan_table[id]) + 1 35*4882a593Smuzhiyun <= next_marker) 36*4882a593Smuzhiyun { 37*4882a593Smuzhiyun-- 38*4882a593Smuzhiyun2.14.2 39*4882a593Smuzhiyun 40