From: B Horn Date: Sun, 12 May 2024 01:48:33 +0000 (+0100) Subject: fs/hfs: Fix stack OOB write with grub_strcpy() X-Git-Tag: archive/raspbian/2.12-8+rpi1^2~69 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=77c09b81b9194fcd624f9bbe6a67c1b27f2b323a;p=grub2.git fs/hfs: Fix stack OOB write with grub_strcpy() Replaced with grub_strlcpy(). Fixes: CVE-2024-45782 Fixes: CVE-2024-56737 Fixes: https://savannah.gnu.org/bugs/?66599 Reported-by: B Horn Signed-off-by: B Horn Reviewed-by: Daniel Kiper Gbp-Pq: Topic cve-2025-jan Gbp-Pq: Name fs-hfs-Fix-stack-OOB-write-with-grub_strcpy.patch --- diff --git a/grub-core/fs/hfs.c b/grub-core/fs/hfs.c index 91dc0e6..920112b 100644 --- a/grub-core/fs/hfs.c +++ b/grub-core/fs/hfs.c @@ -379,7 +379,7 @@ grub_hfs_mount (grub_disk_t disk) volume name. */ key.parent_dir = grub_cpu_to_be32_compile_time (1); key.strlen = data->sblock.volname[0]; - grub_strcpy ((char *) key.str, (char *) (data->sblock.volname + 1)); + grub_strlcpy ((char *) key.str, (char *) (data->sblock.volname + 1), sizeof (key.str)); if (grub_hfs_find_node (data, (char *) &key, data->cat_root, 0, (char *) &dir, sizeof (dir)) == 0)