Bug 15195

Summary: Dunfell: Grub CVE-2020-27749 fix
Product: [Build System, Metadata & Runtime] OE-Core Reporter: jandryuk
Component: oe-core otherAssignee: Steve Sakoman <steve>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium+ CC: randy.macleod
Version: unspecified   
Target Milestone: 3.1.28   
Hardware: x86   
OS: Multiple   
Whiteboard:
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: No (bug/feature does not impact docs)

Description jandryuk 2023-08-17 15:20:00 UTC
CVE-2020-27749 was backported to dunfell in 636aab87bc7e10b4ce0bdaa00dd01416a590a801.  However, grub is building corrupt binaries in at least some cases now.  I have seen this with a custom xen_pvh.  GCC puts some of terminate_arg() into terminate_arg.cold() in a .text.unlikely section.  In the final linked binary, .text.unlikely is ordered ahead of .text.  When the entry point is called, it jumps to the incorrect terminate_arg.cold instead of _start.

The situation is similar to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14367, AFAICT.  The bug there was traced to the same change, but the particular issue was not identified.  I have confirmed that the CFLAGS_remove = "-O2" fixes the issue in dunfell.  The other workaround is to add CFLAGS_append = "-fno-reorder-functions" to prevent the use of .text.unlikely.

I think dunfell should cherry-pick https://github.com/openembedded/openembedded-core/commit/69805629b8f47fd46a37b7c5cc435982e2ac3d1d to resolve the issue.  That keeps dunfell in line with other OE branches.

Thanks!