From af934ea3ba5df1d8f18c141ba1685e70e7356bac Mon Sep 17 00:00:00 2001 From: Warner Losh Date: Tue, 12 Dec 2017 19:26:24 +0000 Subject: [PATCH] Add sanity testing against maximum sane lengths for device paths for loader and kernel. CID: 1383608 Sponsored by: Netflix --- usr.sbin/efibootmgr/efibootmgr.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/usr.sbin/efibootmgr/efibootmgr.c b/usr.sbin/efibootmgr/efibootmgr.c index 95bb18a6f43..ffbbb61776a 100644 --- a/usr.sbin/efibootmgr/efibootmgr.c +++ b/usr.sbin/efibootmgr/efibootmgr.c @@ -650,8 +650,14 @@ make_boot_var(const char *label, const char *loader, const char *kernel, const c kerneldp = NULL; } llen = efidp_size(loaderdp); + if (llen > MAX_DP_LEN) + errx(1, "Loader path too long."); klen = efidp_size(kerneldp); + if (klen > MAX_DP_LEN) + errx(1, "Kernel path too long."); dp = malloc(llen + klen); + if (dp == NULL) + errx(1, "Can't allocate memory for new device paths"); memcpy(dp, loaderdp, llen); if (kerneldp != NULL) memcpy((char *)dp + llen, kerneldp, klen);