summaryrefslogtreecommitdiff
path: root/MdeModulePkg
AgeCommit message (Collapse)AuthorFilesLines
3 daysMdeModulePkg/UefiHiiLib: Fix memory leaks in ValidateQuestionFromVfrQihang Gao1-0/+8
QuestionName is allocated by HiiGetString() but is not released in several code path. This causes memory leaks whenever these paths are taken. Add FreePool (QuestionName) after it is no longer needed. No functional change intended. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
3 daysMdeModulePkg/SetupBrowserDxe: Fix memory leak in GetQuestionDefault()Qihang Gao1-0/+2
StrValue is obtained from HiiGetString(), which allocates a new string buffer. The buffer is used to set DefaultValue->Buffer but is never released, causing a memory leak each time this code path is executed. Add FreePool (StrValue) after it is no longer needed. No functional change intended. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
7 daysMdeModulePkg: Variable: Log Reclaim() completion statusAbdul Lateef Attar1-0/+2
Adds a DEBUG_INFO message when Reclaim() finishes so platform boot logs show whether reclaim ran and what status it returned. This makes it easier to distinguish reclaims impact on boot measurements. Signed-off-by: Abdul Lateef Attar <AbdulLateef.Attar@amd.com>
8 daysMdeModulePkg/UsbBusDxe: Raise TPL to CALLBACK for wanted UsbIo connectMarlboro_Chuang1-0/+9
Raise TPL to TPL_CALLBACK around the ConnectController() call in UsbBusRecursivelyConnectWantedUsbIo() and restore the original TPL afterward. UsbBusRecursivelyConnectWantedUsbIo() is normally reached through the DriverBinding Start routine invoked by gBS->ConnectController(), which runs at TPL_APPLICATION. While the wanted UsbIo handle is being connected, the USB device can be removed. The device removal polling event in UsbBus runs at TPL_CALLBACK. If the connect runs at TPL_APPLICATION, that event can preempt the connection and cause commands to be sent to a stale or non-existent USB device address, producing a lot of timeout transfers. This differs from UsbConnectDriver(), which is called from the enumeration polling event (XHCI async event) and is usually already at TPL_CALLBACK or TPL_NOTIFY. That function uses RestoreTPL()/ RaiseTPL() to ensure ConnectController() runs at TPL_CALLBACK. Signed-off-by: Marlboro_Chuang <marlboro.chuang@dell.com>
8 daysMdeModulePkg/UsbBusDxe: Handle a quirk in Interface descriptorMarlboro_Chuang2-2/+29
Some specific device requires a quirk in the Interface descriptor for InterfaceNumber to work properly [Suggested Solution] Implement the mechanism to ensure the first InterfaceNumber not equal to zero. Signed-off-by: Marlboro_Chuang <marlboro.chuang@dell.com>
10 daysMdeModulePkg: Add EFIAPI to GptLib functionsMichael Kubacki2-0/+6
EFIAPI is required on library interface functions to ensure that the correct calling convention is used. Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
14 daysMdeModulePkg: Update UI strings to indicate case-insensitive key optionsQihang Gao2-6/+6
Update the prompt strings for save/exit and confirm actions to show both uppercase and lowercase key options (e.g., 'Y(y)' and 'N(n)') to make it clear that the system accepts either case. This improves user experience by avoiding confusion about case sensitivity. Affected strings: - ARE_YOU_SURE (CustomizedDisplayLib) - CONFIRM_OPTION (DisplayEngineDxe) - RECONNECT_CHANGES_OPTIONS (DisplayEngineDxe) French translations are updated accordingly. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-09-07MdeModulePkg: Report EFI_SW_DXE_BS_PC_BOOT_OPTION_COMPLETESachin Ganesh1-0/+2
Previously EfiBootManagerBoot reported EFI_SW_DXE_BS_EC_BOOT_OPTION_FAILED when a boot option returned an error, but reported nothing on success. Report the PI 1.10 status code EFI_SW_DXE_BS_PC_BOOT_OPTION_COMPLETE when a boot option loads, executes, and returns success, so status code listeners can tell that a boot option was attempted and that control returned to firmware. Signed-off-by: Sachin Ganesh <sachinganesh@ami.com>
2026-09-03MdeModulePkg/MonotonicCounterRuntimeDxe: Add VarPolicy to the MTC variableMike Turner2-5/+100
Applies a UEFI variable policy to the "MTC" variable to ensure that it is the size of a UINT32 and the variable attributes are restricted to BS, RT, and NV. A protocol dependency on the Variable Policy Protocol is not added to the driver's dependency expression to allow it to be dispatched in firmware that does not have the Variable Policy Protocol installed. Co-authored-by: Michael Kubacki <michael.kubacki@microsoft.com> Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-09-03MdeModulePkg: DxeIpl: Don't Duplicate Mem Alloc Hob for StackOliver Smith-Denny1-15/+10
Currently, DxeIpl will allocate memory for the new DXE stack, which creates a memory allocation HOB for that region. It will then call UpdateStackHob() to find the stack HOB with the old stack info and update the memory address/length to correspond to the new stack. It then creates a new memory allocation HOB for the old stack region as it needs to remain mapped. This ends up creating two memory allocation HOBs for the new stack: a regular memory allocation HOB for the AllocatePages() call and then the stack HOB (which is a memory allocation HOB with a special name). When DXE Core ingests these, it will ignore one of the two HOBs when it goes to allocate memory. However, this is incorrectly describing handoff state. There never should be overlapping memory allocation HOBs. This commit updates DxeIpl behavior to instead find the old stack HOB, convert it to a regular memory allocation HOB, then find the memory allocation HOB for the new stack range and convert it into the stack HOB. Signed-off-by: Oliver Smith-Denny <osde@microsoft.com>
2026-09-02MdeModulePkg: Print unknown error code instead of assertingChris Fernald1-3/+3
DumpUicCmdExecResult & DumpQueryResponseResult are called to dump the result of UIC commands after a failure. Depending on the nature of the failure, not all information may have been properly initialized. This is already handled in callers with existing retry logic, but the assert in the dump command can cause a crash in debug builds for due to hardware race conditions on first attempt. Signed-off-by: Chris Fernald <chfernal@microsoft.com>
2026-08-31MdeModulePkg: Improved error handling in RuntimeDxe Variable driversPaddy Deng (AMI US Holdings Inc)7-67/+504
Some platforms may disable `ASSERT_DEADLOOP_ENABLED` in `PcdDebugPropertyMask`. In this case ASSERT won't hang the machine. Replaced those simple ASSERT with proper error returning handling. Signed-off-by: Paddy Deng (AMI US Holdings Inc) <v-dengpaddy@microsoft.com>
2026-08-28MdeModulePkg/ImagePropertiesRecordLib: Fix incorrect use of sizeofMingjie Shen1-1/+1
In GetFilename(), the post-loop fallback termination used sizeof (EfiFileName), which is the size of the CHAR8 * pointer parameter (8 bytes on X64), not the buffer size. Use EfiFileNameSize - 4 to match the bound of the copy loop above so the string is terminated at the true end of the buffer. Tested on OvmfPkgIa32X64, DEBUG, GCC: DumpImageRecords() prints all runtime image names correctly and NUL-terminated, with no ASSERTs. Signed-off-by: Mingjie Shen <shen497@purdue.edu>
2026-08-28MdeModulePkg/BootMaintenanceManagerUiLib: Change numeric step to 1Qihang Gao1-1/+1
Set the numeric step to 1 to allow +/- key adjustment. Signed-off-by: Qihang Gao <gaoqihang@loongson.cn>
2026-08-27MdeModulePkg: Skip deleted vars in PeiVariable index table searchesAnsen Huang1-0/+9
The Variable PEIM's index table optimization search path incorrectly returns deleted variables instead of valid variables when duplicate variables exist with different states. This occurs when: - One variable has deleted state (VAR_IN_DELETED_TRANSITION & VAR_ADDED, value 0x3C) - One variable has valid state (VAR_ADDED, value 0x3F) - Both variables have the same name and GUID The function should prioritize and return the valid variable, but the index table search was returning the first match regardless of state validity. In the FindVariableEx() index table traversal, the function was not properly validating variable states before returning a match. When CompareWithValidVariable() found a matching variable name and GUID, it would return immediately without checking if the variable state was valid (0x3F) or deleted (0x3C). This issue only affects the index table optimization search path and does not impact the linear traversal search path. The Variable PEIM has two main search mechanisms: 1. Linear traversal search - Walks through the entire variable store checking each header sequentially. This path has correct state validation logic and is unaffected by this issue. 2. Index table optimization search - Uses a gEfiVariableIndexTableGuid HOB to quickly jump to variable locations. This optimization is only active when the platform produces this HOB. This is the path affected by the issue. This commit adds explicit state validation in FindVariableEx() to skip variables with deleted state (0x3C). Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-08-27MdeModulePkg/UefiBootManagerLib: Add constructor to INF fileMichael Kubacki1-0/+1
UefiBootManagerLibConstructor() is a constructor function in BmBoot.c that is missing as the constructor in the INF file. Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-08-26MdeModulePkg/Core/Dxe: Add interrupt-enable nesting guardMichael D Kinney1-0/+20
Add interrupt-enable recursion depth tracking using mInterruptEnableNestDepth and a bounded assertion in CoreSetInterruptState(). This provides early detection for unintended recursive interrupt-enable loops. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2026-08-26MdeModulePkg/Core/Dxe: Refactor CoreSetInterruptState enable pathMichael D Kinney1-7/+6
Refactor the CoreSetInterruptState(TRUE) flow so EnableInterrupt() is invoked through a single call site. Behavior is unchanged: interrupts remain disabled in SMM and are enabled outside SMM. Signed-off-by: Michael D Kinney <michael.d.kinney@intel.com>
2026-08-11MdeModulePkg/UefiHiiLib: Fix regression from 12828Aaron Pop1-1/+0
12828 introduced an ASSERT in HiiGetBrowserData() that fires when InternalHiiBrowserCallback() returns NULL. This is a valid return value indicating the browser has no data for the requested variable, and callers already handle this by checking the FALSE return value. The ASSERT is incorrect because it triggers on a non-error path, causing a crash when the browser callback legitimately returns no data. Remove the unnecessary ASSERT while keeping the existing FALSE return so callers continue to handle this case gracefully. Cc: Qihang Gao <gaoqihang@loongson.cn> Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix unchecked return statusAaron Pop1-0/+3
https://github.com/github/codeql/blob/codeql-cli-2.7.3/csharp/ql/src/API%20Abuse/UncheckedReturnValue.qhelp When a function has a return status, it should be checked to verify the function completed successfully. Failing to check the return status can result in null pointer dereferences or use of uninitialized variables. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop6-11/+55
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix comparison with wider widthsAaron Pop6-27/+27
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type If the narrow type (smaller range) is compared against a wide type (larger range), the narrow value may overflow before reaching the wide value. This can cause unexpected behavior, such as: Infinite loops (loop condition never becomes false). Incorrect logic (comparison results are misleading). Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix conditionally uninitialized variablesAaron Pop4-4/+19
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Security/CWE/CWE-457/ConditionallyUninitializedVariable.qhelp Some local variables, when going through a code path, can end up uninitialized (using the value they had at the start of the function). This is generally due to an error path that can occur based on the library instances, or the unchecked error (i.e. a allocation failing). These variables should be initialized with a known value that will result in the function being able to exit gracefully. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop7-69/+246
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix Comparison overflowAaron Pop2-7/+18
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Security/CWE/CWE-190/ComparisonWithWiderType.qhelp Switch to using SafeUint16Add for calculating offsets into block data. The data being used in the calculation comes from config block strings, and there is no validation of the values before the calculation occurs. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop1-15/+62
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix comparison with wider widthsAaron Pop1-1/+1
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type If the narrow type (smaller range) is compared against a wide type (larger range), the narrow value may overflow before reaching the wide value. This can cause unexpected behavior, such as: Infinite loops (loop condition never becomes false). Incorrect logic (comparison results are misleading). Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop3-6/+18
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop5-10/+55
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix unchecked return statusAaron Pop2-1/+6
https://github.com/github/codeql/blob/codeql-cli-2.7.3/csharp/ql/src/API%20Abuse/UncheckedReturnValue.qhelp When a function has a return status, it should be checked to verify the function completed successfully. Failing to check the return status can result in null pointer dereferences or use of uninitialized variables. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix unchecked return statusAaron Pop2-4/+16
https://github.com/github/codeql/blob/codeql-cli-2.7.3/csharp/ql/src/API%20Abuse/UncheckedReturnValue.qhelp When a function has a return status, it should be checked to verify the function completed successfully. Failing to check the return status can result in null pointer dereferences or use of uninitialized variables. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix missing NULL testsAaron Pop12-131/+327
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-05MdeModulePkg: Fix comparison with wider widthsAaron Pop9-14/+14
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type If the narrow type (smaller range) is compared against a wide type (larger range), the narrow value may overflow before reaching the wide value. This can cause unexpected behavior, such as: Infinite loops (loop condition never becomes false). Incorrect logic (comparison results are misleading). Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-08-01MdeModulePkg/SmbiosDxe: fix table length checkGerd Hoffmann1-2/+2
In case EntryPointStructure does not exist yet use a length of zero instead of skipping the check altogether. Fixes a heap overflow in the following code flow in case the first smbios table installed is larger than SMBIOS_TABLE_MAX_LENGTH. Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2026-08-01MdeModulePkg/NvmExpressHci.c: Save time when BIOS reset with NVMesTheo1-49/+87
Dispatch Shutdown Notification to every NVMe first, then polling every NVMe t omaake sure all NVMe's shutdown processing is completed.This will help to save a lot time when BIOS trigger reset for Servers whose have many NVMes. Tested on a platform with AMD EPYC cpu with 26 NVMes, this method reduce reset time from 3 minutes to 10 seconds. Signed-off-by: Theo <theo.tao@foxmail.com>
2026-07-31MdeModulePkg: MemoryBins: make GoogleTest page-granularity awareJeff Brasen1-6/+36
MemoryBinGoogleTest.PopulatesFromValidHob asserted fixed page counts for each memory type. PopulateMemoryTypeInformation, however, rounds the runtime memory types (EfiReservedMemoryType, EfiACPIMemoryNVS, EfiRuntimeServicesCode, EfiRuntimeServicesData) up to RUNTIME_PAGE_ALLOCATION_GRANULARITY. That granularity equals EFI_PAGE_SIZE on IA32/X64, so the hard-coded values happened to match, but it is 64 KiB on AArch64, where the same inputs round up to different page counts and the test failed. Compute the expected page counts with the same granularity rounding the production code uses, so the test passes on all host architectures instead of only x86. Signed-off-by: Jeff Brasen <jbrasen@nvidia.com>
2026-07-31MdeModulePkg: Host Test: Adding AArch64 targetKun Qin1-1/+1
This change adds the AArch64 target for host based unit tests. Signed-off-by: Kun Qin <kun.qin@microsoft.com>
2026-07-31MdeModulePkg/UsbBusDxe: Fix UsbPortReset might run into recursive loopJared Pan1-19/+24
UsbSelectConfig will introduce the UsbConnectDriver call. If this UsbPortReset is happened in the Usb device driver Start() routine and the device FW can not be recovered by PortReset, the UsbSelectConfig will introduce the recursive loop. [Suggested solution] Since UsbPortReset should not change the Bus Topology, the Reset flow should only SetAddress and reconfigure the device. Signed-off-by: Marlboro Chuang <marlboro.chuang@dell.com> Signed-off-by: Jared Pan <jared.pan@dell.com>
2026-07-31MdeModulePkg/HiiDatabaseDxe: Fix potential intrinsic errorMichael Kubacki1-19/+14
In some VS22 versions, these code patterns (assiging the scalar in a loop) have been found to be converted into calls to the `memcpy` intrinsic. This change updates them to use CopyMem to avoid the potential error. Previous: - MSVC version: 14.31.31103 New: - MSVC version: 14.32.31326 Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-07-30MdeModulePkg: Fix missing NULL testsAaron Pop7-17/+61
https://github.com/github/codeql/blob/codeql-cli-2.7.3/cpp/ql/src/Critical/MissingNullTest.qhelp For items which allocate memory, or get a pointer from another structure, it is important to validate that the pointers are not null before they are dereferenced. Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-07-30MdeModulePkg: Fix comparison with wider widthsAaron Pop1-5/+5
https://codeql.github.com/codeql-query-help/cpp/cpp-comparison-with-wider-type If the narrow type (smaller range) is compared against a wide type (larger range), the narrow value may overflow before reaching the wide value. This can cause unexpected behavior, such as: Infinite loops (loop condition never becomes false). Incorrect logic (comparison results are misleading). Signed-off-by: Aaron Pop <aaronpop@microsoft.com>
2026-07-29Global: Set MarkdownLintCheck plugin to AuditOnlyMichael Kubacki1-0/+8
In preparation for the MarkdownLintCheck plugin being added to the repo, this change defaults the plugin to `AuditOnly` mode in each package. This allows package maintainers to enable the plugin as they see fit. Continuous-integration-options: PatchCheck.ignore-multi-package Signed-off-by: Michael Kubacki <michael.kubacki@microsoft.com>
2026-07-22MdeModulePkg/UsbBusDxe: BOS Descriptor Check for SS DevicesJared Pan5-0/+145
Some SuperSpeed-capable devices may fall back to High-Speed mode and cause subsequent commands to fail. [Suggested Solution] Check the BOS descriptor to verify SuperSpeed support and trigger a port reset if needed to re-enumerate the device properly. Signed-off-by: Marlboro Chuang <marlboro.chuang@dell.com> Signed-off-by: Jared Pan <jared.pan@dell.com>
2026-07-21MdeModulePkg/UsbBusPei: Use dynamic buffer for USB configuration dataDC-Damien2-12/+11
USB devices whose configuration descriptor TotalLength exceeds 1024 bytes (e.g. IR cameras with large descriptor tables) previously hit an EFI_DEVICE_ERROR hard-limit and failed to enumerate in PEI. Replace the fixed array with a UINT8 * pointer and dynamically allocate the exact amount of memory required via PeiServicesAllocatePool() after the TotalLength is learned from the initial 4-byte descriptor probe. Signed-off-by: Damien Chen <damien.chen@dell.com>
2026-07-21MdeModulePkg: Bump the default SMBIOS version to 3.8Rebecca Cran1-1/+1
Commit 7f505d377b44aeee59f34b3d898f6caf0a0df538 in 2024 added the Type 4 field SocketType. Bump the default SMBIOS version to 3.8 in order for the larger table size to be valid. Signed-off-by: Rebecca Cran <rebecca@bsdio.com>
2026-07-21MdeModulePkg/GptLib: Add host-based unit tests for malformed GPT inputRichard Lyu2-3/+571
Extend the GptLib host-based tests with negative cases that guard the security hardening in PartitionValidGptTable(), PartitionCheckGptEntry() and PartitionRestoreGptTable() against future regressions. These tests exercise the shared parser, not the specific fix itself. The new cases drive the parser with malformed GPT structures that an attacker may present: bad signature/revision, header-size boundaries, CRC corruption, MyLBA replay, zero/non-power-of-two entry sizes, LBA multiplication overflow, out-of-range and overlapping entries, and restore failure on write-protected media. The INF file header is updated to note the added malformed coverage. Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Add host-based unit tests for valid GPT behaviorRichard Lyu6-0/+931
Add the positive-path host-based tests for the shared GptLib parser (extracted as part of the parser security hardening), ensuring the tightened checks in PartitionValidGptTable(), PartitionCheckGptEntry() and PartitionRestoreGptTable() do not falsely reject well-formed GPTs. The tests run against an in-memory mock disk and cover accepted primary/backup headers, boundary but legal header/entry sizes, correct entry-status flagging on valid entries, and primary/backup restore round-trips. Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/PartitionDxe: Abort on primary GPT recovery failureRichard Lyu1-10/+21
When the primary GPT is invalid, PartitionInstallGptChildHandles() restores it from the backup and re-validates it. Both the restore write and the re-validation can fail (e.g. write-protected media, or a backup AlternateLBA pointing beyond the device), yet the existing code only logs the failure and parses partitions from a known-invalid PrimaryHeader. Abort GPT processing when either the restore or the validation fails, so partitions are only ever parsed from a validated primary GPT. The backup recovery branch is left unchanged, as the primary is already validated. A device with an unrecoverable primary GPT now installs no child handles instead of using an invalid header. This keeps the table PartitionDxe uses in sync with the one DxeTpm2MeasureBootLib measures into PCR[5]. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Validate GPT header fields before useRichard Lyu1-3/+31
PartitionValidGptTable() checked the signature, header CRC32, MyLBA, the entry-array CRC32 and the entry-array size overflow, but not several other UEFI-mandated GPT header constraints. DxeTpm2MeasureBootLib used to enforce these via Tpm2SanitizeEfiPartitionTableHeader(); once it switched to this shared parser, the checks were lost on the path. Also reject a header unless Header.Revision is GPT_HEADER_REVISION_V1, HeaderSize is at least the 92-byte minimum, NumberOfPartitionEntries is non-zero, SizeOfPartitionEntry is 128 * 2^n, and PartitionEntryLBA * BlockSize cannot overflow. The "entries lie before FirstUsableLBA" rule is intentionally omitted, as this routine also validates the backup header whose entry array follows the usable region. This restores the validation the measurement path lost and, because GptLib is shared, tightens PartitionDxe the same way: malformed headers are now rejected and the parse and measure paths stay identical. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>
2026-07-21MdeModulePkg/GptLib: Extract shareable GPT parser into a libraryRichard Lyu8-590/+707
As reported in CVE-2024-13745 via oss-sec, DxeTpm2MeasureBootLib can measure a partition table that differs from the one parsed by the PartitionDxe driver. To address this, the more complete GPT parsing logic from PartitionDxe is extracted into a standalone GptLib library so it can be shared between PartitionDxe and DxeTpm2MeasureBootLib. This ensures that the exact same partition table measured into PCR[5] is the one parsed and used by the system. PartitionDxe behavior is unchanged. Ref: https://seclists.org/oss-sec/2026/q2/727 Signed-off-by: Richard Lyu <richard.lyu@suse.com>