summaryrefslogtreecommitdiffstats
path: root/meta
diff options
context:
space:
mode:
authorHongxu Jia <hongxu.jia@windriver.com>2026-01-05 14:13:36 +0800
committerPaul Barker <paul@pbarker.dev>2026-05-12 21:31:33 +0100
commitc18ef2583d98ba3cc7f4785f7eec9b992625e6e9 (patch)
tree9b72882fec4f30434d3c22ad5f6e3e932aa04bd9 /meta
parentc71fdaca9c2689847d58c35e0e4a8ab37da51cc5 (diff)
downloadpoky-c18ef2583d98ba3cc7f4785f7eec9b992625e6e9.tar.gz
ovmf: fix CVE-2024-38798
According to [1], EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality. Backport a patch [2] from upstream to fix CVE-2024-38798 [1] https://nvd.nist.gov/vuln/detail/CVE-2024-38798 [2] https://github.com/tianocore/edk2/commit/0cad130cb4885961da201bb9b08424b3fd3d2249 (From OE-Core rev: ed444adf325d3a985ed8f9ae0a009ecbaf67c3fd) Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com> Signed-off-by: Fabien Thomas <fabien.thomas@smile.fr> Signed-off-by: Paul Barker <paul@pbarker.dev>
Diffstat (limited to 'meta')
-rw-r--r--meta/recipes-core/ovmf/ovmf/CVE-2024-38798.patch116
-rw-r--r--meta/recipes-core/ovmf/ovmf_git.bb1
2 files changed, 117 insertions, 0 deletions
diff --git a/meta/recipes-core/ovmf/ovmf/CVE-2024-38798.patch b/meta/recipes-core/ovmf/ovmf/CVE-2024-38798.patch
new file mode 100644
index 0000000000..2d0a73c7a6
--- /dev/null
+++ b/meta/recipes-core/ovmf/ovmf/CVE-2024-38798.patch
@@ -0,0 +1,116 @@
1From 81263e46ad8cf2a6c7d86bc51c95342d07ec31ca Mon Sep 17 00:00:00 2001
2From: Hongxu Jia <hongxu.jia@windriver.com>
3Date: Mon, 5 Jan 2026 13:04:18 +0800
4Subject: [PATCH] MdeModulePkg : Clear keyboard queue buffer after reading
5
6There is a possibility to retrieve user input keystroke data stored in the
7queue buffer via the EFI_SIMPLE_TEXT_INPUT_PROTOCOL pointer. To prevent
8exposure of the password string, clear the queue buffer by filling it
9with zeros after reading.
10
11Signed-off-by: Nick Wang <nick.wang@insyde.com>
12
13CVE: CVE-2024-38798
14Upstream-Status: Backport [https://github.com/tianocore/edk2/commit/0cad130cb4885961da201bb9b08424b3fd3d2249]
15Signed-off-by: Hongxu Jia <hongxu.jia@windriver.com>
16---
17 MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdCtrller.c | 2 ++
18 MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdTextIn.c | 1 +
19 MdeModulePkg/Bus/Usb/UsbKbDxe/KeyBoard.c | 2 +-
20 .../Universal/Console/ConSplitterDxe/ConSplitter.c | 1 +
21 .../Universal/Console/TerminalDxe/TerminalConIn.c | 8 ++++++--
22 5 files changed, 11 insertions(+), 3 deletions(-)
23
24diff --git a/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdCtrller.c b/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdCtrller.c
25index 981309f..32757a7 100644
26--- a/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdCtrller.c
27+++ b/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdCtrller.c
28@@ -650,6 +650,8 @@ PopScancodeBufHead (
29 if (Buf != NULL) {
30 Buf[Index] = Queue->Buffer[Queue->Head];
31 }
32+
33+ Queue->Buffer[Queue->Head] = 0;
34 }
35
36 return EFI_SUCCESS;
37diff --git a/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdTextIn.c b/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdTextIn.c
38index 81d3c6e..e03c88f 100644
39--- a/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdTextIn.c
40+++ b/MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KbdTextIn.c
41@@ -51,6 +51,7 @@ PopEfikeyBufHead (
42 CopyMem (KeyData, &Queue->Buffer[Queue->Head], sizeof (EFI_KEY_DATA));
43 }
44
45+ ZeroMem (&Queue->Buffer[Queue->Head], sizeof (EFI_KEY_DATA));
46 Queue->Head = (Queue->Head + 1) % KEYBOARD_EFI_KEY_MAX_COUNT;
47 return EFI_SUCCESS;
48 }
49diff --git a/MdeModulePkg/Bus/Usb/UsbKbDxe/KeyBoard.c b/MdeModulePkg/Bus/Usb/UsbKbDxe/KeyBoard.c
50index b5a6459..7df1566 100644
51--- a/MdeModulePkg/Bus/Usb/UsbKbDxe/KeyBoard.c
52+++ b/MdeModulePkg/Bus/Usb/UsbKbDxe/KeyBoard.c
53@@ -1840,7 +1840,7 @@ Dequeue (
54 }
55
56 CopyMem (Item, Queue->Buffer[Queue->Head], ItemSize);
57-
58+ ZeroMem (Queue->Buffer[Queue->Head], ItemSize);
59 //
60 // Adjust the head pointer of the FIFO keyboard buffer.
61 //
62diff --git a/MdeModulePkg/Universal/Console/ConSplitterDxe/ConSplitter.c b/MdeModulePkg/Universal/Console/ConSplitterDxe/ConSplitter.c
63index 0a776f3..5c1a35e 100644
64--- a/MdeModulePkg/Universal/Console/ConSplitterDxe/ConSplitter.c
65+++ b/MdeModulePkg/Universal/Console/ConSplitterDxe/ConSplitter.c
66@@ -3537,6 +3537,7 @@ ConSplitterTextInExDequeueKey (
67 &Private->KeyQueue[1],
68 Private->CurrentNumberOfKeys * sizeof (EFI_KEY_DATA)
69 );
70+ ZeroMem (&Private->KeyQueue[Private->CurrentNumberOfKeys], sizeof (EFI_KEY_DATA));
71 return EFI_SUCCESS;
72 }
73
74diff --git a/MdeModulePkg/Universal/Console/TerminalDxe/TerminalConIn.c b/MdeModulePkg/Universal/Console/TerminalDxe/TerminalConIn.c
75index f1d0a34..8aafb4b 100644
76--- a/MdeModulePkg/Universal/Console/TerminalDxe/TerminalConIn.c
77+++ b/MdeModulePkg/Universal/Console/TerminalDxe/TerminalConIn.c
78@@ -760,7 +760,8 @@ RawFiFoRemoveOneKey (
79 return FALSE;
80 }
81
82- *Output = TerminalDevice->RawFiFo->Data[Head];
83+ *Output = TerminalDevice->RawFiFo->Data[Head];
84+ TerminalDevice->RawFiFo->Data[Head] = 0;
85
86 TerminalDevice->RawFiFo->Head = (UINT8)((Head + 1) % (RAW_FIFO_MAX_NUMBER + 1));
87
88@@ -881,6 +882,7 @@ EfiKeyFiFoForNotifyRemoveOneKey (
89 }
90
91 CopyMem (Output, &EfiKeyFiFo->Data[Head], sizeof (EFI_INPUT_KEY));
92+ ZeroMem (&EfiKeyFiFo->Data[Head], sizeof (EFI_INPUT_KEY));
93
94 EfiKeyFiFo->Head = (UINT8)((Head + 1) % (FIFO_MAX_NUMBER + 1));
95
96@@ -1032,6 +1034,7 @@ EfiKeyFiFoRemoveOneKey (
97 }
98
99 CopyMem (Output, &TerminalDevice->EfiKeyFiFo->Data[Head], sizeof (EFI_INPUT_KEY));
100+ ZeroMem (&TerminalDevice->EfiKeyFiFo->Data[Head], sizeof (EFI_INPUT_KEY));
101
102 TerminalDevice->EfiKeyFiFo->Head = (UINT8)((Head + 1) % (FIFO_MAX_NUMBER + 1));
103
104@@ -1142,7 +1145,8 @@ UnicodeFiFoRemoveOneKey (
105 Head = TerminalDevice->UnicodeFiFo->Head;
106 ASSERT (Head < FIFO_MAX_NUMBER + 1);
107
108- *Output = TerminalDevice->UnicodeFiFo->Data[Head];
109+ *Output = TerminalDevice->UnicodeFiFo->Data[Head];
110+ TerminalDevice->UnicodeFiFo->Data[Head] = 0;
111
112 TerminalDevice->UnicodeFiFo->Head = (UINT8)((Head + 1) % (FIFO_MAX_NUMBER + 1));
113 }
114--
1152.34.1
116
diff --git a/meta/recipes-core/ovmf/ovmf_git.bb b/meta/recipes-core/ovmf/ovmf_git.bb
index fd5ff25dc9..4e6227f484 100644
--- a/meta/recipes-core/ovmf/ovmf_git.bb
+++ b/meta/recipes-core/ovmf/ovmf_git.bb
@@ -39,6 +39,7 @@ SRC_URI = "gitsm://github.com/tianocore/edk2.git;branch=master;protocol=https \
39 file://CVE-2025-2296-7.patch \ 39 file://CVE-2025-2296-7.patch \
40 file://CVE-2025-2296-8.patch \ 40 file://CVE-2025-2296-8.patch \
41 file://CVE-2025-2296-9.patch \ 41 file://CVE-2025-2296-9.patch \
42 file://CVE-2024-38798.patch \
42 " 43 "
43 44
44PV = "edk2-stable202402" 45PV = "edk2-stable202402"