video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG
authorDaniel Axtens <dja@axtens.net>
Fri, 8 Mar 2024 11:47:20 +0000 (22:47 +1100)
committerMiao Wang <shankerwangmiao@gmail.com>
Sun, 15 Feb 2026 13:50:20 +0000 (13:50 +0000)
commit38fcd9e392401bf28599729cfbd2f8c18390af7f
treef652f81b3ff6c17368644d2d72356b79545b2c3f
parent6b512fa44cabb6277479010a370194e023d39d1c
video/readers/jpeg: Do not permit duplicate SOF0 markers in JPEG

Otherwise a subsequent header could change the height and width
allowing future OOB writes.

Fixes: CVE-2024-45774
Reported-by: Nils Langius <nils@langius.de>
Signed-off-by: Daniel Axtens <dja@axtens.net>
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
Gbp-Pq: Topic cve-2025-jan
Gbp-Pq: Name video-readers-jpeg-Do-not-permit-duplicate-SOF0-markers-i.patch
grub-core/video/readers/jpeg.c