[Bug] integer overflow in GPT entry allocation causes OOB read on 32-bit targets
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Estancado
- Stack tecnológico
- c
- Área
- embedded-iot, security
Línea de trabajo
Comienza en components/drivers/block/partitions/efi.c, después revisa rt_size_t en include/rttypes.h y la configuración de max_partitions en components/drivers/sdio/dev_block.c. Verifica el sondeo de GPT en un destino de 32 bits con la cabecera preparada descrita; se considera terminado cuando se rechaza overflow y la iteración no puede superar el número de entradas GPT asignadas.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
RT-Thread Version
master (verified on commit 6a635e32d9f39ea015824927cee492620a05212f); also present in v5.2.2, v5.2.1, and v5.2.0
Hardware Type/Architectures
Any 32-bit BSP with GPT partition probing enabled (RT_BLK_PARTITION_EFI)
Develop Toolchain
Other
Describe the bug
This issue is independent from #11259, which reports a different bug in read_lba().
A 32-bit-only memory-safety issue exists in components/drivers/block/partitions/efi.c. The GPT parser computes the allocation size for the partition
entry array using rt_size_t, which is 32-bit on 32-bit builds, but later iterates over the entry array using the original untrusted on-disk entry count.
Affected code:
/* components/drivers/block/partitions/efi.c */
count = (rt_size_t)rt_le32_to_cpu(gpt->num_partition_entries) *
rt_le32_to_cpu(gpt->sizeof_partition_entry);
pte = rt_malloc(count);
Later:
/* components/drivers/block/partitions/efi.c */
entries_nr = rt_le32_to_cpu(gpt->num_partition_entries);
for (int i = 0; i < entries_nr && i < disk->max_partitions; ++i)
{
rt_uint64_t start = rt_le64_to_cpu(ptes[i].starting_lba);
rt_uint64_t size = rt_le64_to_cpu(ptes[i].ending_lba) -
rt_le64_to_cpu(ptes[i].starting_lba) + 1ULL;
if (!is_pte_valid(&ptes[i], last_lba(disk)))
{
continue;
}
...
}
On 32-bit RT-Thread builds, rt_size_t is 32-bit:
/* include/rttypes.h */
#ifdef ARCH_CPU_64BIT
typedef rt_uint64_t rt_ubase_t;
#else
typedef rt_uint32_t rt_ubase_t;
#endif
...
typedef rt_ubase_t rt_size_t;
The code also later enforces:
rt_le32_to_cpu((*gpt)->sizeof_partition_entry) == sizeof(gpt_entry)
So the allocation is effectively based on:
num_partition_entries * 128
This multiplication can wrap on 32-bit targets and produce a much smaller non-zero allocation.
For example, with a crafted GPT header:
- num_partition_entries = 0x02000004
- sizeof_partition_entry = 128
the true product is 0x100000200, but the 32-bit wrapped allocation size becomes 0x200 (512 bytes), which only holds 4 GPT entries.
However, efi_partition() still trusts the original entries_nr = 0x02000004 and iterates until i < disk->max_partitions.
Many common MMC/SD block devices default to 16 partitions:
/* components/drivers/sdio/dev_block.c */
#ifndef RT_MMCSD_MAX_PARTITION
#define RT_MMCSD_MAX_PARTITION 16
#endif
...
blk_dev->parent.max_partitions = RT_MMCSD_MAX_PARTITION;
As a result, on a common 32-bit MMC/SD configuration, the parser may allocate space for only 4 entries but still read ptes[4] through ptes[15], causing an
out-of-bounds read from heap memory.
Steps to reproduce the behavior
- Build RT-Thread for a 32-bit target with GPT partition probing enabled.
- Present a crafted GPT disk image or block device to the system.
- Set sizeof_partition_entry = 128.
- Set num_partition_entries = 0x02000004.
- Trigger normal partition probing.
Expected behavior
The parser should reject GPT headers when:
- num_partition_entries * sizeof_partition_entry overflows
- the computed allocation size cannot represent the claimed number of entries
- later iteration would exceed the actually allocated entry count
Actual behavior
The allocation size wraps on 32-bit builds, but later code still indexes the GPT entry array using the original untrusted entry count, leading to out-of-
bounds reads and undefined behavior. Depending on heap layout and target configuration, this may cause crashes or cause heap data to be interpreted as fake
GPT entries.
Suggested fix
- Reject integer overflow before allocation. For example, validate:
entries_nr = rt_le32_to_cpu(gpt->num_partition_entries);
entry_size = rt_le32_to_cpu(gpt->sizeof_partition_entry);
if (entry_size != sizeof(gpt_entry) ||
entries_nr == 0 ||
entries_nr > RT_SIZE_MAX / entry_size)
{
return RT_NULL;
}
- Use the validated entry count consistently after allocation instead of reusing the raw on-disk value.
- Bound the later iteration by the number of entries actually allocated, for example:
validated_entries = count / sizeof(gpt_entry);
for (i = 0; i < validated_entries && i < disk->max_partitions; ++i)
- More generally, avoid recomputing lengths from untrusted GPT header fields after allocation unless the same overflow checks are applied again.
Kindly let me know if you intend to request a CVE ID upon confirmation of the vulnerability.
Other additional context
No response
- Lenguaje dominante
- C
- Estrellas
- 12.3k
- Forks
- 5.5k
- Merge medio
- 3 d 8 h
- PR fusionados (30 d)
- 27
Preparar el entorno
Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de RT-Thread/rt-thread
-
[Bug] [netdev] ping crashes the shell with a division by zero when the target is unreachable (received == 0)Posiblemente ocupada @r3wretrhy la tomó hace 3 días. Abiertobug Component component: net
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
RT-Thread/rt-thread#11852 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[bsp][stm32][bluepill] README「快速上手」缺少重新生成 MDK 工程这一步,按文档操作无法编译通过Posiblemente ocupada @moment-NEW la tomó hace 6 días. Abiertoin progress
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
RT-Thread/rt-thread#11818 · 4 comentarios · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
BSP BSP: Loongson bug RT-Smart
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RT-Thread/rt-thread#11717 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
Arch: RISC-V BSP BSP: HPMicro bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
RT-Thread/rt-thread#11687 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
RT-Thread/rt-thread#11472 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de RT-Thread/rt-thread
Issues similares
-
IO.get_env on Node truncates names at embedded NULPosiblemente ocupada @Yi-111-a la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
HigherOrderCO/Bend#1449 · 1 comentario ·
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
FujiNetWIFI/fujinet-firmware#1872 ·
Los mantenedores suelen responder en 1 día
-
bug C/C++ code
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
webarkit/WebARKitLib#84 ·
Los mantenedores suelen responder en 1 día
-
Bad device URI "://" on network printers. Printing stopped working between 2.4.19 and 2.4.20Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
OpenPrinting/cups#1751 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
es-ude/OnDeviceTraining#488 ·
Los mantenedores suelen responder en 1 día