Bug 15195 - Dunfell: Grub CVE-2020-27749 fix
Summary: Dunfell: Grub CVE-2020-27749 fix
Status: RESOLVED FIXED
Alias: None
Product: OE-Core
Classification: Build System, Metadata & Runtime
Component: oe-core other (show other bugs)
Version: unspecified
Hardware: x86 Multiple
: Medium+ normal
Target Milestone: 3.1.28
Assignee: Steve Sakoman
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2023-08-17 15:20 UTC by jandryuk
Modified: 2023-09-14 15:06 UTC (History)
1 user (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: No (bug/feature does not impact docs)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description jandryuk 2023-08-17 15:20:00 UTC
CVE-2020-27749 was backported to dunfell in 636aab87bc7e10b4ce0bdaa00dd01416a590a801.  However, grub is building corrupt binaries in at least some cases now.  I have seen this with a custom xen_pvh.  GCC puts some of terminate_arg() into terminate_arg.cold() in a .text.unlikely section.  In the final linked binary, .text.unlikely is ordered ahead of .text.  When the entry point is called, it jumps to the incorrect terminate_arg.cold instead of _start.

The situation is similar to https://bugzilla.yoctoproject.org/show_bug.cgi?id=14367, AFAICT.  The bug there was traced to the same change, but the particular issue was not identified.  I have confirmed that the CFLAGS_remove = "-O2" fixes the issue in dunfell.  The other workaround is to add CFLAGS_append = "-fno-reorder-functions" to prevent the use of .text.unlikely.

I think dunfell should cherry-pick https://github.com/openembedded/openembedded-core/commit/69805629b8f47fd46a37b7c5cc435982e2ac3d1d to resolve the issue.  That keeps dunfell in line with other OE branches.

Thanks!