]> dgit.raspbian.org Git - grub2.git/commit
net/tftp: Fix stack buffer overflow in tftp_open()
authorB Horn <b@horn.uk>
Thu, 18 Apr 2024 16:32:34 +0000 (17:32 +0100)
committerAurelien Jarno <aurel32@debian.org>
Thu, 30 Apr 2026 19:02:01 +0000 (21:02 +0200)
commit2d47537ec2675a2ef501c0e9e90e4b94c25ba99a
tree608e702670f91b0620867d66dcda1632e4370b08
parent6a546f27864ef0ed3130f2208c54bb438cdd0e67
net/tftp: Fix stack buffer overflow in tftp_open()

An overly long filename can be passed to tftp_open() which would cause
grub_normalize_filename() to write out of bounds.

Fixed by adding an extra argument to grub_normalize_filename() for the
space available, making it act closer to a strlcpy(). As several fixed
strings are strcpy()'d after into the same buffer, their total length is
checked to see if they exceed the remaining space in the buffer. If so,
return an error.

On the occasion simplify code a bit by removing unneeded rrqlen zeroing.

Reported-by: B Horn <b@horn.uk>
Signed-off-by: B Horn <b@horn.uk>
Reviewed-by: Daniel Kiper <daniel.kiper@oracle.com>
Gbp-Pq: Topic cve-2025-jan
Gbp-Pq: Name net-tftp-Fix-stack-buffer-overflow-in-tftp_open.patch
grub-core/net/tftp.c