1*4882a593SmuzhiyunFrom e623866d9286410156e8b9d2c82d6253a1b22d08 Mon Sep 17 00:00:00 2001 2*4882a593SmuzhiyunFrom: Daniel Axtens <dja@axtens.net> 3*4882a593SmuzhiyunDate: Tue, 6 Jul 2021 18:51:35 +1000 4*4882a593SmuzhiyunSubject: [PATCH] video/readers/png: Drop greyscale support to fix heap 5*4882a593Smuzhiyun out-of-bounds write 6*4882a593Smuzhiyun 7*4882a593SmuzhiyunA 16-bit greyscale PNG without alpha is processed in the following loop: 8*4882a593Smuzhiyun 9*4882a593Smuzhiyun for (i = 0; i < (data->image_width * data->image_height); 10*4882a593Smuzhiyun i++, d1 += 4, d2 += 2) 11*4882a593Smuzhiyun { 12*4882a593Smuzhiyun d1[R3] = d2[1]; 13*4882a593Smuzhiyun d1[G3] = d2[1]; 14*4882a593Smuzhiyun d1[B3] = d2[1]; 15*4882a593Smuzhiyun } 16*4882a593Smuzhiyun 17*4882a593SmuzhiyunThe increment of d1 is wrong. d1 is incremented by 4 bytes per iteration, 18*4882a593Smuzhiyunbut there are only 3 bytes allocated for storage. This means that image 19*4882a593Smuzhiyundata will overwrite somewhat-attacker-controlled parts of memory - 3 bytes 20*4882a593Smuzhiyunout of every 4 following the end of the image. 21*4882a593Smuzhiyun 22*4882a593SmuzhiyunThis has existed since greyscale support was added in 2013 in commit 23*4882a593Smuzhiyun3ccf16dff98f (grub-core/video/readers/png.c: Support grayscale). 24*4882a593Smuzhiyun 25*4882a593SmuzhiyunSaving starfield.png as a 16-bit greyscale image without alpha in the gimp 26*4882a593Smuzhiyunand attempting to load it causes grub-emu to crash - I don't think this code 27*4882a593Smuzhiyunhas ever worked. 28*4882a593Smuzhiyun 29*4882a593SmuzhiyunDelete all PNG greyscale support. 30*4882a593Smuzhiyun 31*4882a593SmuzhiyunFixes: CVE-2021-3695 32*4882a593Smuzhiyun 33*4882a593SmuzhiyunSigned-off-by: Daniel Axtens <dja@axtens.net> 34*4882a593SmuzhiyunReviewed-by: Daniel Kiper <daniel.kiper@oracle.com> 35*4882a593Smuzhiyun 36*4882a593SmuzhiyunUpstream-Status: Backport 37*4882a593SmuzhiyunCVE: CVE-2021-3695 38*4882a593Smuzhiyun 39*4882a593SmuzhiyunReference to upstream patch: 40*4882a593Smuzhiyunhttps://git.savannah.gnu.org/cgit/grub.git/commit/?id=e623866d9286410156e8b9d2c82d6253a1b22d08 41*4882a593Smuzhiyun 42*4882a593SmuzhiyunSigned-off-by: Yongxin Liu <yongxin.liu@windriver.com> 43*4882a593Smuzhiyun--- 44*4882a593Smuzhiyun grub-core/video/readers/png.c | 87 +++-------------------------------- 45*4882a593Smuzhiyun 1 file changed, 7 insertions(+), 80 deletions(-) 46*4882a593Smuzhiyun 47*4882a593Smuzhiyundiff --git a/grub-core/video/readers/png.c b/grub-core/video/readers/png.c 48*4882a593Smuzhiyunindex 35ae553c8..a3161e25b 100644 49*4882a593Smuzhiyun--- a/grub-core/video/readers/png.c 50*4882a593Smuzhiyun+++ b/grub-core/video/readers/png.c 51*4882a593Smuzhiyun@@ -100,7 +100,7 @@ struct grub_png_data 52*4882a593Smuzhiyun 53*4882a593Smuzhiyun unsigned image_width, image_height; 54*4882a593Smuzhiyun int bpp, is_16bit; 55*4882a593Smuzhiyun- int raw_bytes, is_gray, is_alpha, is_palette; 56*4882a593Smuzhiyun+ int raw_bytes, is_alpha, is_palette; 57*4882a593Smuzhiyun int row_bytes, color_bits; 58*4882a593Smuzhiyun grub_uint8_t *image_data; 59*4882a593Smuzhiyun 60*4882a593Smuzhiyun@@ -296,13 +296,13 @@ grub_png_decode_image_header (struct grub_png_data *data) 61*4882a593Smuzhiyun data->bpp = 3; 62*4882a593Smuzhiyun else 63*4882a593Smuzhiyun { 64*4882a593Smuzhiyun- data->is_gray = 1; 65*4882a593Smuzhiyun- data->bpp = 1; 66*4882a593Smuzhiyun+ return grub_error (GRUB_ERR_BAD_FILE_TYPE, 67*4882a593Smuzhiyun+ "png: color type not supported"); 68*4882a593Smuzhiyun } 69*4882a593Smuzhiyun 70*4882a593Smuzhiyun if ((color_bits != 8) && (color_bits != 16) 71*4882a593Smuzhiyun && (color_bits != 4 72*4882a593Smuzhiyun- || !(data->is_gray || data->is_palette))) 73*4882a593Smuzhiyun+ || !data->is_palette)) 74*4882a593Smuzhiyun return grub_error (GRUB_ERR_BAD_FILE_TYPE, 75*4882a593Smuzhiyun "png: bit depth must be 8 or 16"); 76*4882a593Smuzhiyun 77*4882a593Smuzhiyun@@ -331,7 +331,7 @@ grub_png_decode_image_header (struct grub_png_data *data) 78*4882a593Smuzhiyun } 79*4882a593Smuzhiyun 80*4882a593Smuzhiyun #ifndef GRUB_CPU_WORDS_BIGENDIAN 81*4882a593Smuzhiyun- if (data->is_16bit || data->is_gray || data->is_palette) 82*4882a593Smuzhiyun+ if (data->is_16bit || data->is_palette) 83*4882a593Smuzhiyun #endif 84*4882a593Smuzhiyun { 85*4882a593Smuzhiyun data->image_data = grub_calloc (data->image_height, data->row_bytes); 86*4882a593Smuzhiyun@@ -899,27 +899,8 @@ grub_png_convert_image (struct grub_png_data *data) 87*4882a593Smuzhiyun int shift; 88*4882a593Smuzhiyun int mask = (1 << data->color_bits) - 1; 89*4882a593Smuzhiyun unsigned j; 90*4882a593Smuzhiyun- if (data->is_gray) 91*4882a593Smuzhiyun- { 92*4882a593Smuzhiyun- /* Generic formula is 93*4882a593Smuzhiyun- (0xff * i) / ((1U << data->color_bits) - 1) 94*4882a593Smuzhiyun- but for allowed bit depth of 1, 2 and for it's 95*4882a593Smuzhiyun- equivalent to 96*4882a593Smuzhiyun- (0xff / ((1U << data->color_bits) - 1)) * i 97*4882a593Smuzhiyun- Precompute the multipliers to avoid division. 98*4882a593Smuzhiyun- */ 99*4882a593Smuzhiyun- 100*4882a593Smuzhiyun- const grub_uint8_t multipliers[5] = { 0xff, 0xff, 0x55, 0x24, 0x11 }; 101*4882a593Smuzhiyun- for (i = 0; i < (1U << data->color_bits); i++) 102*4882a593Smuzhiyun- { 103*4882a593Smuzhiyun- grub_uint8_t col = multipliers[data->color_bits] * i; 104*4882a593Smuzhiyun- palette[i][0] = col; 105*4882a593Smuzhiyun- palette[i][1] = col; 106*4882a593Smuzhiyun- palette[i][2] = col; 107*4882a593Smuzhiyun- } 108*4882a593Smuzhiyun- } 109*4882a593Smuzhiyun- else 110*4882a593Smuzhiyun- grub_memcpy (palette, data->palette, 3 << data->color_bits); 111*4882a593Smuzhiyun+ 112*4882a593Smuzhiyun+ grub_memcpy (palette, data->palette, 3 << data->color_bits); 113*4882a593Smuzhiyun d1c = d1; 114*4882a593Smuzhiyun d2c = d2; 115*4882a593Smuzhiyun for (j = 0; j < data->image_height; j++, d1c += data->image_width * 3, 116*4882a593Smuzhiyun@@ -957,60 +938,6 @@ grub_png_convert_image (struct grub_png_data *data) 117*4882a593Smuzhiyun return; 118*4882a593Smuzhiyun } 119*4882a593Smuzhiyun 120*4882a593Smuzhiyun- if (data->is_gray) 121*4882a593Smuzhiyun- { 122*4882a593Smuzhiyun- switch (data->bpp) 123*4882a593Smuzhiyun- { 124*4882a593Smuzhiyun- case 4: 125*4882a593Smuzhiyun- /* 16-bit gray with alpha. */ 126*4882a593Smuzhiyun- for (i = 0; i < (data->image_width * data->image_height); 127*4882a593Smuzhiyun- i++, d1 += 4, d2 += 4) 128*4882a593Smuzhiyun- { 129*4882a593Smuzhiyun- d1[R4] = d2[3]; 130*4882a593Smuzhiyun- d1[G4] = d2[3]; 131*4882a593Smuzhiyun- d1[B4] = d2[3]; 132*4882a593Smuzhiyun- d1[A4] = d2[1]; 133*4882a593Smuzhiyun- } 134*4882a593Smuzhiyun- break; 135*4882a593Smuzhiyun- case 2: 136*4882a593Smuzhiyun- if (data->is_16bit) 137*4882a593Smuzhiyun- /* 16-bit gray without alpha. */ 138*4882a593Smuzhiyun- { 139*4882a593Smuzhiyun- for (i = 0; i < (data->image_width * data->image_height); 140*4882a593Smuzhiyun- i++, d1 += 4, d2 += 2) 141*4882a593Smuzhiyun- { 142*4882a593Smuzhiyun- d1[R3] = d2[1]; 143*4882a593Smuzhiyun- d1[G3] = d2[1]; 144*4882a593Smuzhiyun- d1[B3] = d2[1]; 145*4882a593Smuzhiyun- } 146*4882a593Smuzhiyun- } 147*4882a593Smuzhiyun- else 148*4882a593Smuzhiyun- /* 8-bit gray with alpha. */ 149*4882a593Smuzhiyun- { 150*4882a593Smuzhiyun- for (i = 0; i < (data->image_width * data->image_height); 151*4882a593Smuzhiyun- i++, d1 += 4, d2 += 2) 152*4882a593Smuzhiyun- { 153*4882a593Smuzhiyun- d1[R4] = d2[1]; 154*4882a593Smuzhiyun- d1[G4] = d2[1]; 155*4882a593Smuzhiyun- d1[B4] = d2[1]; 156*4882a593Smuzhiyun- d1[A4] = d2[0]; 157*4882a593Smuzhiyun- } 158*4882a593Smuzhiyun- } 159*4882a593Smuzhiyun- break; 160*4882a593Smuzhiyun- /* 8-bit gray without alpha. */ 161*4882a593Smuzhiyun- case 1: 162*4882a593Smuzhiyun- for (i = 0; i < (data->image_width * data->image_height); 163*4882a593Smuzhiyun- i++, d1 += 3, d2++) 164*4882a593Smuzhiyun- { 165*4882a593Smuzhiyun- d1[R3] = d2[0]; 166*4882a593Smuzhiyun- d1[G3] = d2[0]; 167*4882a593Smuzhiyun- d1[B3] = d2[0]; 168*4882a593Smuzhiyun- } 169*4882a593Smuzhiyun- break; 170*4882a593Smuzhiyun- } 171*4882a593Smuzhiyun- return; 172*4882a593Smuzhiyun- } 173*4882a593Smuzhiyun- 174*4882a593Smuzhiyun { 175*4882a593Smuzhiyun /* Only copy the upper 8 bit. */ 176*4882a593Smuzhiyun #ifndef GRUB_CPU_WORDS_BIGENDIAN 177*4882a593Smuzhiyun-- 178*4882a593Smuzhiyun2.34.1 179*4882a593Smuzhiyun 180