1*4882a593SmuzhiyunFrom e623866d9286410156e8b9d2c82d6253a1b22d08 Mon Sep 17 00:00:00 2001
2*4882a593SmuzhiyunFrom: Daniel Axtens <dja@axtens.net>
3*4882a593SmuzhiyunDate: Tue, 6 Jul 2021 18:51:35 +1000
4*4882a593SmuzhiyunSubject: [PATCH] video/readers/png: Drop greyscale support to fix heap
5*4882a593Smuzhiyun out-of-bounds write
6*4882a593Smuzhiyun
7*4882a593SmuzhiyunA 16-bit greyscale PNG without alpha is processed in the following loop:
8*4882a593Smuzhiyun
9*4882a593Smuzhiyun      for (i = 0; i < (data->image_width * data->image_height);
10*4882a593Smuzhiyun	   i++, d1 += 4, d2 += 2)
11*4882a593Smuzhiyun	{
12*4882a593Smuzhiyun	  d1[R3] = d2[1];
13*4882a593Smuzhiyun	  d1[G3] = d2[1];
14*4882a593Smuzhiyun	  d1[B3] = d2[1];
15*4882a593Smuzhiyun	}
16*4882a593Smuzhiyun
17*4882a593SmuzhiyunThe increment of d1 is wrong. d1 is incremented by 4 bytes per iteration,
18*4882a593Smuzhiyunbut there are only 3 bytes allocated for storage. This means that image
19*4882a593Smuzhiyundata will overwrite somewhat-attacker-controlled parts of memory - 3 bytes
20*4882a593Smuzhiyunout of every 4 following the end of the image.
21*4882a593Smuzhiyun
22*4882a593SmuzhiyunThis has existed since greyscale support was added in 2013 in commit
23*4882a593Smuzhiyun3ccf16dff98f (grub-core/video/readers/png.c: Support grayscale).
24*4882a593Smuzhiyun
25*4882a593SmuzhiyunSaving starfield.png as a 16-bit greyscale image without alpha in the gimp
26*4882a593Smuzhiyunand attempting to load it causes grub-emu to crash - I don't think this code
27*4882a593Smuzhiyunhas ever worked.
28*4882a593Smuzhiyun
29*4882a593SmuzhiyunDelete all PNG greyscale support.
30*4882a593Smuzhiyun
31*4882a593SmuzhiyunFixes: CVE-2021-3695
32*4882a593Smuzhiyun
33*4882a593SmuzhiyunSigned-off-by: Daniel Axtens <dja@axtens.net>
34*4882a593SmuzhiyunReviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
35*4882a593Smuzhiyun
36*4882a593SmuzhiyunUpstream-Status: Backport
37*4882a593SmuzhiyunCVE: CVE-2021-3695
38*4882a593Smuzhiyun
39*4882a593SmuzhiyunReference to upstream patch:
40*4882a593Smuzhiyunhttps://git.savannah.gnu.org/cgit/grub.git/commit/?id=e623866d9286410156e8b9d2c82d6253a1b22d08
41*4882a593Smuzhiyun
42*4882a593SmuzhiyunSigned-off-by: Yongxin Liu <yongxin.liu@windriver.com>
43*4882a593Smuzhiyun---
44*4882a593Smuzhiyun grub-core/video/readers/png.c | 87 +++--------------------------------
45*4882a593Smuzhiyun 1 file changed, 7 insertions(+), 80 deletions(-)
46*4882a593Smuzhiyun
47*4882a593Smuzhiyundiff --git a/grub-core/video/readers/png.c b/grub-core/video/readers/png.c
48*4882a593Smuzhiyunindex 35ae553c8..a3161e25b 100644
49*4882a593Smuzhiyun--- a/grub-core/video/readers/png.c
50*4882a593Smuzhiyun+++ b/grub-core/video/readers/png.c
51*4882a593Smuzhiyun@@ -100,7 +100,7 @@ struct grub_png_data
52*4882a593Smuzhiyun
53*4882a593Smuzhiyun   unsigned image_width, image_height;
54*4882a593Smuzhiyun   int bpp, is_16bit;
55*4882a593Smuzhiyun-  int raw_bytes, is_gray, is_alpha, is_palette;
56*4882a593Smuzhiyun+  int raw_bytes, is_alpha, is_palette;
57*4882a593Smuzhiyun   int row_bytes, color_bits;
58*4882a593Smuzhiyun   grub_uint8_t *image_data;
59*4882a593Smuzhiyun
60*4882a593Smuzhiyun@@ -296,13 +296,13 @@ grub_png_decode_image_header (struct grub_png_data *data)
61*4882a593Smuzhiyun     data->bpp = 3;
62*4882a593Smuzhiyun   else
63*4882a593Smuzhiyun     {
64*4882a593Smuzhiyun-      data->is_gray = 1;
65*4882a593Smuzhiyun-      data->bpp = 1;
66*4882a593Smuzhiyun+      return grub_error (GRUB_ERR_BAD_FILE_TYPE,
67*4882a593Smuzhiyun+			 "png: color type not supported");
68*4882a593Smuzhiyun     }
69*4882a593Smuzhiyun
70*4882a593Smuzhiyun   if ((color_bits != 8) && (color_bits != 16)
71*4882a593Smuzhiyun       && (color_bits != 4
72*4882a593Smuzhiyun-	  || !(data->is_gray || data->is_palette)))
73*4882a593Smuzhiyun+	  || !data->is_palette))
74*4882a593Smuzhiyun     return grub_error (GRUB_ERR_BAD_FILE_TYPE,
75*4882a593Smuzhiyun                        "png: bit depth must be 8 or 16");
76*4882a593Smuzhiyun
77*4882a593Smuzhiyun@@ -331,7 +331,7 @@ grub_png_decode_image_header (struct grub_png_data *data)
78*4882a593Smuzhiyun     }
79*4882a593Smuzhiyun
80*4882a593Smuzhiyun #ifndef GRUB_CPU_WORDS_BIGENDIAN
81*4882a593Smuzhiyun-  if (data->is_16bit || data->is_gray || data->is_palette)
82*4882a593Smuzhiyun+  if (data->is_16bit || data->is_palette)
83*4882a593Smuzhiyun #endif
84*4882a593Smuzhiyun     {
85*4882a593Smuzhiyun       data->image_data = grub_calloc (data->image_height, data->row_bytes);
86*4882a593Smuzhiyun@@ -899,27 +899,8 @@ grub_png_convert_image (struct grub_png_data *data)
87*4882a593Smuzhiyun       int shift;
88*4882a593Smuzhiyun       int mask = (1 << data->color_bits) - 1;
89*4882a593Smuzhiyun       unsigned j;
90*4882a593Smuzhiyun-      if (data->is_gray)
91*4882a593Smuzhiyun-	{
92*4882a593Smuzhiyun-	  /* Generic formula is
93*4882a593Smuzhiyun-	     (0xff * i) / ((1U << data->color_bits) - 1)
94*4882a593Smuzhiyun-	     but for allowed bit depth of 1, 2 and for it's
95*4882a593Smuzhiyun-	     equivalent to
96*4882a593Smuzhiyun-	     (0xff / ((1U << data->color_bits) - 1)) * i
97*4882a593Smuzhiyun-	     Precompute the multipliers to avoid division.
98*4882a593Smuzhiyun-	  */
99*4882a593Smuzhiyun-
100*4882a593Smuzhiyun-	  const grub_uint8_t multipliers[5] = { 0xff, 0xff, 0x55, 0x24, 0x11 };
101*4882a593Smuzhiyun-	  for (i = 0; i < (1U << data->color_bits); i++)
102*4882a593Smuzhiyun-	    {
103*4882a593Smuzhiyun-	      grub_uint8_t col = multipliers[data->color_bits] * i;
104*4882a593Smuzhiyun-	      palette[i][0] = col;
105*4882a593Smuzhiyun-	      palette[i][1] = col;
106*4882a593Smuzhiyun-	      palette[i][2] = col;
107*4882a593Smuzhiyun-	    }
108*4882a593Smuzhiyun-	}
109*4882a593Smuzhiyun-      else
110*4882a593Smuzhiyun-	grub_memcpy (palette, data->palette, 3 << data->color_bits);
111*4882a593Smuzhiyun+
112*4882a593Smuzhiyun+      grub_memcpy (palette, data->palette, 3 << data->color_bits);
113*4882a593Smuzhiyun       d1c = d1;
114*4882a593Smuzhiyun       d2c = d2;
115*4882a593Smuzhiyun       for (j = 0; j < data->image_height; j++, d1c += data->image_width * 3,
116*4882a593Smuzhiyun@@ -957,60 +938,6 @@ grub_png_convert_image (struct grub_png_data *data)
117*4882a593Smuzhiyun       return;
118*4882a593Smuzhiyun     }
119*4882a593Smuzhiyun
120*4882a593Smuzhiyun-  if (data->is_gray)
121*4882a593Smuzhiyun-    {
122*4882a593Smuzhiyun-      switch (data->bpp)
123*4882a593Smuzhiyun-	{
124*4882a593Smuzhiyun-	case 4:
125*4882a593Smuzhiyun-	  /* 16-bit gray with alpha.  */
126*4882a593Smuzhiyun-	  for (i = 0; i < (data->image_width * data->image_height);
127*4882a593Smuzhiyun-	       i++, d1 += 4, d2 += 4)
128*4882a593Smuzhiyun-	    {
129*4882a593Smuzhiyun-	      d1[R4] = d2[3];
130*4882a593Smuzhiyun-	      d1[G4] = d2[3];
131*4882a593Smuzhiyun-	      d1[B4] = d2[3];
132*4882a593Smuzhiyun-	      d1[A4] = d2[1];
133*4882a593Smuzhiyun-	    }
134*4882a593Smuzhiyun-	  break;
135*4882a593Smuzhiyun-	case 2:
136*4882a593Smuzhiyun-	  if (data->is_16bit)
137*4882a593Smuzhiyun-	    /* 16-bit gray without alpha.  */
138*4882a593Smuzhiyun-	    {
139*4882a593Smuzhiyun-	      for (i = 0; i < (data->image_width * data->image_height);
140*4882a593Smuzhiyun-		   i++, d1 += 4, d2 += 2)
141*4882a593Smuzhiyun-		{
142*4882a593Smuzhiyun-		  d1[R3] = d2[1];
143*4882a593Smuzhiyun-		  d1[G3] = d2[1];
144*4882a593Smuzhiyun-		  d1[B3] = d2[1];
145*4882a593Smuzhiyun-		}
146*4882a593Smuzhiyun-	    }
147*4882a593Smuzhiyun-	  else
148*4882a593Smuzhiyun-	    /* 8-bit gray with alpha.  */
149*4882a593Smuzhiyun-	    {
150*4882a593Smuzhiyun-	      for (i = 0; i < (data->image_width * data->image_height);
151*4882a593Smuzhiyun-		   i++, d1 += 4, d2 += 2)
152*4882a593Smuzhiyun-		{
153*4882a593Smuzhiyun-		  d1[R4] = d2[1];
154*4882a593Smuzhiyun-		  d1[G4] = d2[1];
155*4882a593Smuzhiyun-		  d1[B4] = d2[1];
156*4882a593Smuzhiyun-		  d1[A4] = d2[0];
157*4882a593Smuzhiyun-		}
158*4882a593Smuzhiyun-	    }
159*4882a593Smuzhiyun-	  break;
160*4882a593Smuzhiyun-	  /* 8-bit gray without alpha.  */
161*4882a593Smuzhiyun-	case 1:
162*4882a593Smuzhiyun-	  for (i = 0; i < (data->image_width * data->image_height);
163*4882a593Smuzhiyun-	       i++, d1 += 3, d2++)
164*4882a593Smuzhiyun-	    {
165*4882a593Smuzhiyun-	      d1[R3] = d2[0];
166*4882a593Smuzhiyun-	      d1[G3] = d2[0];
167*4882a593Smuzhiyun-	      d1[B3] = d2[0];
168*4882a593Smuzhiyun-	    }
169*4882a593Smuzhiyun-	  break;
170*4882a593Smuzhiyun-	}
171*4882a593Smuzhiyun-      return;
172*4882a593Smuzhiyun-    }
173*4882a593Smuzhiyun-
174*4882a593Smuzhiyun     {
175*4882a593Smuzhiyun   /* Only copy the upper 8 bit.  */
176*4882a593Smuzhiyun #ifndef GRUB_CPU_WORDS_BIGENDIAN
177*4882a593Smuzhiyun--
178*4882a593Smuzhiyun2.34.1
179*4882a593Smuzhiyun
180