1*4882a593SmuzhiyunFrom 5f5eb7ca8e971227e95745abe541df3e1509360e Mon Sep 17 00:00:00 2001
2*4882a593SmuzhiyunFrom: Darren Kenny <darren.kenny@oracle.com>
3*4882a593SmuzhiyunDate: Fri, 4 Dec 2020 15:39:00 +0000
4*4882a593SmuzhiyunSubject: [PATCH] video/readers/jpeg: Test for an invalid next marker reference
5*4882a593Smuzhiyun from a jpeg file
6*4882a593Smuzhiyun
7*4882a593SmuzhiyunWhile it may never happen, and potentially could be caught at the end of
8*4882a593Smuzhiyunthe function, it is worth checking up front for a bad reference to the
9*4882a593Smuzhiyunnext marker just in case of a maliciously crafted file being provided.
10*4882a593Smuzhiyun
11*4882a593SmuzhiyunFixes: CID 73694
12*4882a593Smuzhiyun
13*4882a593SmuzhiyunSigned-off-by: Darren Kenny <darren.kenny@oracle.com>
14*4882a593SmuzhiyunReviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
15*4882a593SmuzhiyunSigned-off-by: Stefan Sørensen <stefan.sorensen@spectralink.com>
16*4882a593Smuzhiyun---
17*4882a593Smuzhiyun grub-core/video/readers/jpeg.c | 6 ++++++
18*4882a593Smuzhiyun 1 file changed, 6 insertions(+)
19*4882a593Smuzhiyun
20*4882a593Smuzhiyundiff --git a/grub-core/video/readers/jpeg.c b/grub-core/video/readers/jpeg.c
21*4882a593Smuzhiyunindex 31359a4..0b6ce3c 100644
22*4882a593Smuzhiyun--- a/grub-core/video/readers/jpeg.c
23*4882a593Smuzhiyun+++ b/grub-core/video/readers/jpeg.c
24*4882a593Smuzhiyun@@ -253,6 +253,12 @@ grub_jpeg_decode_quan_table (struct grub_jpeg_data *data)
25*4882a593Smuzhiyun   next_marker = data->file->offset;
26*4882a593Smuzhiyun   next_marker += grub_jpeg_get_word (data);
27*4882a593Smuzhiyun
28*4882a593Smuzhiyun+  if (next_marker > data->file->size)
29*4882a593Smuzhiyun+    {
30*4882a593Smuzhiyun+      /* Should never be set beyond the size of the file. */
31*4882a593Smuzhiyun+      return grub_error (GRUB_ERR_BAD_FILE_TYPE, "jpeg: invalid next reference");
32*4882a593Smuzhiyun+    }
33*4882a593Smuzhiyun+
34*4882a593Smuzhiyun   while (data->file->offset + sizeof (data->quan_table[id]) + 1
35*4882a593Smuzhiyun 	 <= next_marker)
36*4882a593Smuzhiyun     {
37*4882a593Smuzhiyun--
38*4882a593Smuzhiyun2.14.2
39*4882a593Smuzhiyun
40