Fix CVE-2023-45229、CVE-2023-45230、CVE-2023-45231、CVE-2023-45232、CVE-2023-45233、CVE-2023-45234、CVE-2023-45235 Signed-off-by: yexiao <yexiao7@huawei.com> (cherry picked from commit aa6a1dc11863945714f63746d5f1159ed3ede3e7)
63 lines
1.6 KiB
Diff
63 lines
1.6 KiB
Diff
From e5b0312aae033a90d4c5be31daead52549edf2f9 Mon Sep 17 00:00:00 2001
|
|
From: Doug Flick <dougflick@microsoft.com>
|
|
Date: Fri, 26 Jan 2024 05:54:48 +0800
|
|
Subject: [PATCH 06/19] NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45231 Patch
|
|
|
|
REF:https://bugzilla.tianocore.org/show_bug.cgi?id=4536
|
|
|
|
Bug Overview:
|
|
PixieFail Bug #3
|
|
CVE-2023-45231
|
|
CVSS 6.5 : CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
|
CWE-125 Out-of-bounds Read
|
|
|
|
Out-of-bounds read when handling a ND Redirect message with truncated
|
|
options
|
|
|
|
Change Overview:
|
|
|
|
Adds a check to prevent truncated options from being parsed
|
|
+ //
|
|
+ // Cannot process truncated options.
|
|
+ // Cannot process options with a length of 0 as there is no Type
|
|
field.
|
|
+ //
|
|
+ if (OptionLen < sizeof (IP6_OPTION_HEADER)) {
|
|
+ return FALSE;
|
|
+ }
|
|
|
|
Cc: Saloni Kasbekar <saloni.kasbekar@intel.com>
|
|
Cc: Zachary Clark-williams <zachary.clark-williams@intel.com>
|
|
|
|
Signed-off-by: Doug Flick [MSFT] <doug.edk2@gmail.com>
|
|
Reviewed-by: Saloni Kasbekar <saloni.kasbekar@intel.com>
|
|
|
|
reference: https://github.com/tianocore/edk2/pull/5352
|
|
Signed-off-by: yexiao <yexiao7@huawei.com>
|
|
---
|
|
NetworkPkg/Ip6Dxe/Ip6Option.c | 8 ++++++++
|
|
1 file changed, 8 insertions(+)
|
|
|
|
diff --git a/NetworkPkg/Ip6Dxe/Ip6Option.c b/NetworkPkg/Ip6Dxe/Ip6Option.c
|
|
index 199eea12..780771f2 100644
|
|
--- a/NetworkPkg/Ip6Dxe/Ip6Option.c
|
|
+++ b/NetworkPkg/Ip6Dxe/Ip6Option.c
|
|
@@ -137,6 +137,14 @@ Ip6IsNDOptionValid (
|
|
return FALSE;
|
|
}
|
|
|
|
+ //
|
|
+ // Cannot process truncated options.
|
|
+ // Cannot process options with a length of 0 as there is no Type field.
|
|
+ //
|
|
+ if (OptionLen < sizeof (IP6_OPTION_HEADER)) {
|
|
+ return FALSE;
|
|
+ }
|
|
+
|
|
Offset = 0;
|
|
|
|
//
|
|
--
|
|
2.33.0
|
|
|