Branch: refs/heads/master
Home: https://github.com/tianocore/edk2
Commit: d3dcf3dafa5527c706f56ef1c56a69c02aa9c4a4
https://github.com/tianocore/edk2/commit/d3dcf3dafa5527c706f56ef1c56a69c02aa9c4a4
Author: Kun Qin <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
M ArmPkg/Drivers/MmCommunicationPei/MmCommunicationPei.c
M ArmPkg/Drivers/MmCommunicationPei/MmCommunicationPei.inf
Log Message:
-----------
ArmPkg: MmCommunicationPei: Use SafeIntLib for safe arithmetic operations
This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication message length before using.
Signed-off-by: Kun Qin <[email protected]>
Commit: b7181b56db84cbf618fc379ad1f1bfab9fe29d4d
https://github.com/tianocore/edk2/commit/b7181b56db84cbf618fc379ad1f1bfab9fe29d4d
Author: Kun Qin <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
M ArmPkg/Drivers/MmCommunicationDxe/MmCommunication.c
M ArmPkg/Drivers/MmCommunicationDxe/MmCommunication.inf
Log Message:
-----------
ArmPkg: MmCommunicationDxe: Use SafeIntLib for safe arithmetic operations
This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.
Signed-off-by: Kun Qin <[email protected]>
Commit: a75d2d7eb62b8bce249a7c85f423fc24dc533193
https://github.com/tianocore/edk2/commit/a75d2d7eb62b8bce249a7c85f423fc24dc533193
Author: Kun Qin <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
M
ArmPkg/Library/ArmStandaloneMmCoreEntryPoint/ArmStandaloneMmCoreEntryPoint.c
M
ArmPkg/Library/ArmStandaloneMmCoreEntryPoint/ArmStandaloneMmCoreEntryPoint.inf
Log Message:
-----------
ArmPkg: ArmStandaloneMmCoreEntryPoint: Use SafeIntLib for arithmetics
This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.
Signed-off-by: Kun Qin <[email protected]>
Commit: eae187d0355d78dfa7a03006fe06693c3bd9690e
https://github.com/tianocore/edk2/commit/eae187d0355d78dfa7a03006fe06693c3bd9690e
Author: Kun Qin <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
M StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c
M StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.h
M StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.inf
Log Message:
-----------
StandaloneMmPkg: StandaloneMmIplPei: Use SafeIntLib for safe arithmetics
This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.
Signed-off-by: Kun Qin <[email protected]>
Commit: 97f4cc402a80b1964f4f97b19039205ef8b9aa52
https://github.com/tianocore/edk2/commit/97f4cc402a80b1964f4f97b19039205ef8b9aa52
Author: Kun Qin <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
M StandaloneMmPkg/Core/StandaloneMmCore.c
M StandaloneMmPkg/Core/StandaloneMmCore.h
M StandaloneMmPkg/Core/StandaloneMmCore.inf
Log Message:
-----------
StandaloneMmPkg: StandaloneMmCore: Use SafeIntLib for arithmetics
This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.
Signed-off-by: Kun Qin <[email protected]>
Commit: 73075417b0bc6d3ec40e8ec060f858bc7036954b
https://github.com/tianocore/edk2/commit/73075417b0bc6d3ec40e8ec060f858bc7036954b
Author: Kun Qin <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
M StandaloneMmPkg/Drivers/MmCommunicationDxe/MmCommunicationDxe.c
M StandaloneMmPkg/Drivers/MmCommunicationDxe/MmCommunicationDxe.h
M StandaloneMmPkg/Drivers/MmCommunicationDxe/MmCommunicationDxe.inf
Log Message:
-----------
StandaloneMmPkg: MmCommunicationDxe: Add integer overflow check
`ProcessCommunicationBuffer()` computes BufferSize by adding a fixed
offset (24 bytes) to an attacker-controlled MessageLength (UINT64):
`BufferSize = OFFSET_OF(EFI_MM_COMMUNICATE_HEADER, Data) +
CommunicateHeader->MessageLength;`
When `MessageLength >= 0xFFFFFFFFFFFFFFE8`, the addition wraps to a small
value (0–23 bytes) after UINTN truncation.
The subsequent bounds check evaluates FALSE on the wrapped value,
bypassing size validation and allowing CopyMem to proceed with a
corrupted size into the fixed MM communication buffer.
This change added an overflow check before the addition - rejects with
EFI_INVALID_PARAMETER if `MessageLength` is greater than `MAX_UINTN -
OFFSET_OF(EFI_MM_COMMUNICATE_HEADER, Data).`
Co-authored-by: Gowtham Manikandan <[email protected]>
Signed-off-by: Kun Qin <[email protected]>
Commit: 046b1471e1688e6c756a17fbe9c4057701a0c383
https://github.com/tianocore/edk2/commit/046b1471e1688e6c756a17fbe9c4057701a0c383
Author: Gowtham Manikandan <[email protected]>
Date: 2026-09-02 (Wed, 02 Sep 2026)
Changed paths:
A
StandaloneMmPkg/Drivers/MmCommunicationDxe/GoogleTest/MmCommunicationDxeGoogleTest.cpp
A
StandaloneMmPkg/Drivers/MmCommunicationDxe/GoogleTest/MmCommunicationDxeGoogleTest.inf
M StandaloneMmPkg/StandaloneMmPkg.ci.yaml
A StandaloneMmPkg/Test/StandaloneMmPkgHostTest.dsc
Log Message:
-----------
StandaloneMmPkg: MmCommunicationDxe: Created GoogleTests
This change adds 5 unit tests to cover the incoming buffer validation
routine in the MmCommunicate function.
Signed-off-by: Kun Qin <[email protected]>
Compare: https://github.com/tianocore/edk2/compare/0ea22ef04f3b...046b1471e168
To unsubscribe from these emails, change your notification settings at
https://github.com/tianocore/edk2/settings/notifications
_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits