Commit bf21dc59 authored by Mickaël Salaün's avatar Mickaël Salaün Committed by Jarkko Sakkinen

certs: Make blacklist_vet_description() more strict

Before exposing this new key type to user space, make sure that only
meaningful blacklisted hashes are accepted.  This is also checked for
builtin blacklisted hashes, but a following commit make sure that the
user will notice (at built time) and will fix the configuration if it
already included errors.

Check that a blacklist key description starts with a valid prefix and
then a valid hexadecimal string.

Cc: David Howells <dhowells@redhat.com>
Cc: David Woodhouse <dwmw2@infradead.org>
Cc: Eric Snowberg <eric.snowberg@oracle.com>
Signed-off-by: default avatarMickaël Salaün <mic@linux.microsoft.com>
Reviewed-by: default avatarJarkko Sakkinen <jarkko@kernel.org>
Link: https://lore.kernel.org/r/20210712170313.884724-4-mic@digikod.netSigned-off-by: default avatarJarkko Sakkinen <jarkko@kernel.org>
parent 141e5239
...@@ -19,6 +19,16 @@ ...@@ -19,6 +19,16 @@
#include "blacklist.h" #include "blacklist.h"
#include "common.h" #include "common.h"
/*
* According to crypto/asymmetric_keys/x509_cert_parser.c:x509_note_pkey_algo(),
* the size of the currently longest supported hash algorithm is 512 bits,
* which translates into 128 hex characters.
*/
#define MAX_HASH_LEN 128
static const char tbs_prefix[] = "tbs";
static const char bin_prefix[] = "bin";
static struct key *blacklist_keyring; static struct key *blacklist_keyring;
#ifdef CONFIG_SYSTEM_REVOCATION_LIST #ifdef CONFIG_SYSTEM_REVOCATION_LIST
...@@ -32,24 +42,40 @@ extern __initconst const unsigned long revocation_certificate_list_size; ...@@ -32,24 +42,40 @@ extern __initconst const unsigned long revocation_certificate_list_size;
*/ */
static int blacklist_vet_description(const char *desc) static int blacklist_vet_description(const char *desc)
{ {
int n = 0; int i, prefix_len, tbs_step = 0, bin_step = 0;
if (*desc == ':') /* The following algorithm only works if prefix lengths match. */
return -EINVAL; BUILD_BUG_ON(sizeof(tbs_prefix) != sizeof(bin_prefix));
for (; *desc; desc++) prefix_len = sizeof(tbs_prefix) - 1;
if (*desc == ':') for (i = 0; *desc; desc++, i++) {
goto found_colon; if (*desc == ':') {
if (tbs_step == prefix_len)
goto found_colon;
if (bin_step == prefix_len)
goto found_colon;
return -EINVAL;
}
if (i >= prefix_len)
return -EINVAL;
if (*desc == tbs_prefix[i])
tbs_step++;
if (*desc == bin_prefix[i])
bin_step++;
}
return -EINVAL; return -EINVAL;
found_colon: found_colon:
desc++; desc++;
for (; *desc; desc++) { for (i = 0; *desc && i < MAX_HASH_LEN; desc++, i++) {
if (!isxdigit(*desc) || isupper(*desc)) if (!isxdigit(*desc) || isupper(*desc))
return -EINVAL; return -EINVAL;
n++;
} }
if (*desc)
/* The hash is greater than MAX_HASH_LEN. */
return -ENOPKG;
if (n == 0 || n & 1) /* Checks for an even number of hexadecimal characters. */
if (i == 0 || i & 1)
return -EINVAL; return -EINVAL;
return 0; return 0;
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment