| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 12 days | MdeModulePkg: Add EFIAPI to GptLib functions | Michael Kubacki | 1 | -0/+3 | |
| EFIAPI is required on library interface functions to ensure that the correct calling convention is used. Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com> | |||||
| 2026-07-21 | MdeModulePkg/GptLib: Validate GPT header fields before use | Richard Lyu | 1 | -3/+31 | |
| PartitionValidGptTable() checked the signature, header CRC32, MyLBA, the entry-array CRC32 and the entry-array size overflow, but not several other UEFI-mandated GPT header constraints. DxeTpm2MeasureBootLib used to enforce these via Tpm2SanitizeEfiPartitionTableHeader(); once it switched to this shared parser, the checks were lost on the path. Also reject a header unless Header.Revision is GPT_HEADER_REVISION_V1, HeaderSize is at least the 92-byte minimum, NumberOfPartitionEntries is non-zero, SizeOfPartitionEntry is 128 * 2^n, and PartitionEntryLBA * BlockSize cannot overflow. The "entries lie before FirstUsableLBA" rule is intentionally omitted, as this routine also validates the backup header whose entry array follows the usable region. This restores the validation the measurement path lost and, because GptLib is shared, tightens PartitionDxe the same way: malformed headers are now rejected and the parse and measure paths stay identical. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com> | |||||
| 2026-07-21 | MdeModulePkg/GptLib: Extract shareable GPT parser into a library | Richard Lyu | 1 | -0/+548 | |
| As reported in CVE-2024-13745 via oss-sec, DxeTpm2MeasureBootLib can measure a partition table that differs from the one parsed by the PartitionDxe driver. To address this, the more complete GPT parsing logic from PartitionDxe is extracted into a standalone GptLib library so it can be shared between PartitionDxe and DxeTpm2MeasureBootLib. This ensures that the exact same partition table measured into PCR[5] is the one parsed and used by the system. PartitionDxe behavior is unchanged. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com> | |||||
