video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG
authorDaniel Axtens <dja@axtens.net>
Fri, 8 Mar 2024 11:47:20 +0000 (22:47 +1100)
committerFelix Zielcke <fzielcke@z-51.de>
Thu, 3 Jul 2025 16:35:51 +0000 (18:35 +0200)
commit02e1d82185dfd09f637b8b7493974aad588173c2
tree5561841176d795ba5b5398a5c19252b03c7e1f37
parent38e01ec9131aeb00d0048c67a27a58e724d055f2
video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG

Otherwise a subsequent header could change the height and width
allowing future OOB writes.

Fixes: CVE-2024-45774
Reported-by: Nils Langius <nils@langius.de>
Signed-off-by: Daniel Axtens <dja@axtens.net>
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
Gbp-Pq: Topic cve-2025-jan
Gbp-Pq: Name video-readers-jpeg-Do-not-permit-duplicate-SOF0-markers-i.patch
grub-core/video/readers/jpeg.c