Skip to content

FAPI IMA eventlog: bound the event name read by the template size - #3156

Open
ManoharPaturi wants to merge 1 commit into
tpm2-software:masterfrom
ManoharPaturi:fix-ima-eventname-bounds
Open

ManoharPaturi wants to merge 1 commit into
tpm2-software:masterfrom
ManoharPaturi:fix-ima-eventname-bounds

Conversation

@ManoharPaturi

Copy link
Copy Markdown

Problem

eventname_cb() reads the IMA event name with an unbounded strlen (src/tss2-fapi/ifapi_ima_eventlog.c:360 — the line even carries a // TODO check note):

size = strlen((const char *)&buffer[*offset]); // TODO check
if (size > TCG_EVENT_NAME_LEN_MAX + 1) { ... }

For an old-format ima event whose name field is not NUL-terminated (a corrupt or hostile measurement log), strlen runs past the template buffer before any length check runs.

Confirmed with AddressSanitizer against current master using a crafted old-format event: READ of size 257 ... 0 bytes after 276-byte region in eventname_cb ← convert_ima_event_buffer ← ifapi_read_ima_event_log. The IMA log path is reachable through the public FAPI eventlog API and the ima_log_file configuration.

Fix

Bound the scan with memchr over the remaining template bytes and reject unterminated names with TSS2_FAPI_RC_BAD_VALUE.

Verification

Sanitizers clean on the crafted input after the fix; the existing test/unit/fapi-ima-fuzzing.c harness takes such a .bin payload directly for a regression case.

Copilot AI balanced review requested due to automatic review settings September 29, 2026 15:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@moritzbuhl
moritzbuhl force-pushed the fix-ima-eventname-bounds branch from 3755bbf to f132850 Compare October 2, 2026 05:21

@JuergenReppSIT JuergenReppSIT left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Small style nit: please declare nul together with the other local variables at the start of the function (next to size) instead of in the middle of the block. This matches the style used in the rest of this file, where declarations are grouped at the top of the block, and keeps the function consistent with its surroundings.

Signed-off-by: Manohar Paturi <manoharpaturi@users.noreply.github.com>
@ManoharPaturi
ManoharPaturi force-pushed the fix-ima-eventname-bounds branch from f132850 to 72a5620 Compare October 5, 2026 14:14
@ManoharPaturi

ManoharPaturi commented Oct 5, 2026 •

Copy link
Copy Markdown
Author

@JuergenReppSIT Done,the nul declaration now sits with the other local variables at the top of the function, next to size, and the assignment stays where the bounds check has passed. Amended into the same commit so the diff stays single-purpose.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants