]> git.ipfire.org Git - thirdparty/grub.git/commitdiff
font: Do not load more than one NAME section
authorDaniel Kiper <daniel.kiper@oracle.com>
Tue, 7 Jul 2020 13:36:26 +0000 (15:36 +0200)
committerDaniel Kiper <daniel.kiper@oracle.com>
Wed, 29 Jul 2020 14:55:48 +0000 (16:55 +0200)
The GRUB font file can have one NAME section only. Though if somebody
crafts a broken font file with many NAME sections and loads it then the
GRUB leaks memory. So, prevent against that by loading first NAME
section and failing in controlled way on following one.

Reported-by: Chris Coulson <chris.coulson@canonical.com>
Signed-off-by: Daniel Kiper <daniel.kiper@oracle.com>
Reviewed-by: Jan Setje-Eilers <jan.setjeeilers@oracle.com>
grub-core/font/font.c

index 5edb477ac2e792a4ec5e773c1b6fbbf84a65b795..d09bb38d8964c0e18bd910fa3c7e909ef7372a4e 100644 (file)
@@ -532,6 +532,12 @@ grub_font_load (const char *filename)
       if (grub_memcmp (section.name, FONT_FORMAT_SECTION_NAMES_FONT_NAME,
                       sizeof (FONT_FORMAT_SECTION_NAMES_FONT_NAME) - 1) == 0)
        {
+         if (font->name != NULL)
+           {
+             grub_error (GRUB_ERR_BAD_FONT, "invalid font file: too many NAME sections");
+             goto fail;
+           }
+
          font->name = read_section_as_string (&section);
          if (!font->name)
            goto fail;