<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>15195</bug_id>
          
          <creation_ts>2023-08-17 15:20:00 +0000</creation_ts>
          <short_desc>Dunfell: Grub CVE-2020-27749 fix</short_desc>
          <delta_ts>2023-09-14 15:06:12 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>oe-core other</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium+</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>3.1.28</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jandryuk</reporter>
          <assigned_to name="Steve Sakoman">steve</assigned_to>
          <cc>randy.macleod</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>96270</commentid>
    <comment_count>0</comment_count>
    <who name="">jandryuk</who>
    <bug_when>2023-08-17 15:20:00 +0000</bug_when>
    <thetext>CVE-2020-27749 was backported to dunfell in 636aab87bc7e10b4ce0bdaa00dd01416a590a801.  However, grub is building corrupt binaries in at least some cases now.  I have seen this with a custom xen_pvh.  GCC puts some of terminate_arg() into terminate_arg.cold() in a .text.unlikely section.  In the final linked binary, .text.unlikely is ordered ahead of .text.  When the entry point is called, it jumps to the incorrect terminate_arg.cold instead of _start.

The situation is similar to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14367, AFAICT.  The bug there was traced to the same change, but the particular issue was not identified.  I have confirmed that the CFLAGS_remove = &quot;-O2&quot; fixes the issue in dunfell.  The other workaround is to add CFLAGS_append = &quot;-fno-reorder-functions&quot; to prevent the use of .text.unlikely.

I think dunfell should cherry-pick https://github.com/openembedded/openembedded-core/commit/69805629b8f47fd46a37b7c5cc435982e2ac3d1d to resolve the issue.  That keeps dunfell in line with other OE branches.

Thanks!</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>96412</commentid>
    <comment_count>1</comment_count>
    <who name="Steve Sakoman">steve</who>
    <bug_when>2023-09-14 15:06:12 +0000</bug_when>
    <thetext>Fixed: 

https://git.yoctoproject.org/poky/commit/?h=dunfell&amp;id=b1fdc92450ba1f3869116d88bd92a5a75b8e9f87</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>