Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: d3dcf3dafa5527c706f56ef1c56a69c02aa9c4a4
      
https://github.com/tianocore/edk2/commit/d3dcf3dafa5527c706f56ef1c56a69c02aa9c4a4
  Author: Kun Qin <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    M ArmPkg/Drivers/MmCommunicationPei/MmCommunicationPei.c
    M ArmPkg/Drivers/MmCommunicationPei/MmCommunicationPei.inf

  Log Message:
  -----------
  ArmPkg: MmCommunicationPei: Use SafeIntLib for safe arithmetic operations

This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication message length before using.

Signed-off-by: Kun Qin <[email protected]>


  Commit: b7181b56db84cbf618fc379ad1f1bfab9fe29d4d
      
https://github.com/tianocore/edk2/commit/b7181b56db84cbf618fc379ad1f1bfab9fe29d4d
  Author: Kun Qin <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    M ArmPkg/Drivers/MmCommunicationDxe/MmCommunication.c
    M ArmPkg/Drivers/MmCommunicationDxe/MmCommunication.inf

  Log Message:
  -----------
  ArmPkg: MmCommunicationDxe: Use SafeIntLib for safe arithmetic operations

This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.

Signed-off-by: Kun Qin <[email protected]>


  Commit: a75d2d7eb62b8bce249a7c85f423fc24dc533193
      
https://github.com/tianocore/edk2/commit/a75d2d7eb62b8bce249a7c85f423fc24dc533193
  Author: Kun Qin <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    M 
ArmPkg/Library/ArmStandaloneMmCoreEntryPoint/ArmStandaloneMmCoreEntryPoint.c
    M 
ArmPkg/Library/ArmStandaloneMmCoreEntryPoint/ArmStandaloneMmCoreEntryPoint.inf

  Log Message:
  -----------
  ArmPkg: ArmStandaloneMmCoreEntryPoint: Use SafeIntLib for arithmetics

This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.

Signed-off-by: Kun Qin <[email protected]>


  Commit: eae187d0355d78dfa7a03006fe06693c3bd9690e
      
https://github.com/tianocore/edk2/commit/eae187d0355d78dfa7a03006fe06693c3bd9690e
  Author: Kun Qin <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    M StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.c
    M StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.h
    M StandaloneMmPkg/Drivers/StandaloneMmIplPei/StandaloneMmIplPei.inf

  Log Message:
  -----------
  StandaloneMmPkg: StandaloneMmIplPei: Use SafeIntLib for safe arithmetics

This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.

Signed-off-by: Kun Qin <[email protected]>


  Commit: 97f4cc402a80b1964f4f97b19039205ef8b9aa52
      
https://github.com/tianocore/edk2/commit/97f4cc402a80b1964f4f97b19039205ef8b9aa52
  Author: Kun Qin <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    M StandaloneMmPkg/Core/StandaloneMmCore.c
    M StandaloneMmPkg/Core/StandaloneMmCore.h
    M StandaloneMmPkg/Core/StandaloneMmCore.inf

  Log Message:
  -----------
  StandaloneMmPkg: StandaloneMmCore: Use SafeIntLib for arithmetics

This change adds the SafeIntLib to communication input routine to
validate the incoming MM communication buffer length before using.

Signed-off-by: Kun Qin <[email protected]>


  Commit: 73075417b0bc6d3ec40e8ec060f858bc7036954b
      
https://github.com/tianocore/edk2/commit/73075417b0bc6d3ec40e8ec060f858bc7036954b
  Author: Kun Qin <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    M StandaloneMmPkg/Drivers/MmCommunicationDxe/MmCommunicationDxe.c
    M StandaloneMmPkg/Drivers/MmCommunicationDxe/MmCommunicationDxe.h
    M StandaloneMmPkg/Drivers/MmCommunicationDxe/MmCommunicationDxe.inf

  Log Message:
  -----------
  StandaloneMmPkg: MmCommunicationDxe: Add integer overflow check

`ProcessCommunicationBuffer()` computes BufferSize by adding a fixed
offset (24 bytes) to an attacker-controlled MessageLength (UINT64):

`BufferSize = OFFSET_OF(EFI_MM_COMMUNICATE_HEADER, Data) +
CommunicateHeader->MessageLength;`

When `MessageLength >= 0xFFFFFFFFFFFFFFE8`, the addition wraps to a small
value (0–23 bytes) after UINTN truncation.

The subsequent bounds check evaluates FALSE on the wrapped value,
bypassing size validation and allowing CopyMem to proceed with a
corrupted size into the fixed MM communication buffer.

This change added an overflow check before the addition - rejects with
EFI_INVALID_PARAMETER if `MessageLength` is greater than `MAX_UINTN -
OFFSET_OF(EFI_MM_COMMUNICATE_HEADER, Data).`

Co-authored-by: Gowtham Manikandan <[email protected]>
Signed-off-by: Kun Qin <[email protected]>


  Commit: 046b1471e1688e6c756a17fbe9c4057701a0c383
      
https://github.com/tianocore/edk2/commit/046b1471e1688e6c756a17fbe9c4057701a0c383
  Author: Gowtham Manikandan <[email protected]>
  Date:   2026-09-02 (Wed, 02 Sep 2026)

  Changed paths:
    A 
StandaloneMmPkg/Drivers/MmCommunicationDxe/GoogleTest/MmCommunicationDxeGoogleTest.cpp
    A 
StandaloneMmPkg/Drivers/MmCommunicationDxe/GoogleTest/MmCommunicationDxeGoogleTest.inf
    M StandaloneMmPkg/StandaloneMmPkg.ci.yaml
    A StandaloneMmPkg/Test/StandaloneMmPkgHostTest.dsc

  Log Message:
  -----------
  StandaloneMmPkg: MmCommunicationDxe: Created GoogleTests

This change adds 5 unit tests to cover the incoming buffer validation
routine in the MmCommunicate function.

Signed-off-by: Kun Qin <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/0ea22ef04f3b...046b1471e168

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to