Skip to content

Fix unbounded recursion (DoS) in UefiParser.parse_firmware_volume via zero-length FV header - #115

Open
sys-xmlcli wants to merge 1 commit into
intel:mainfrom
sys-xmlcli:PTK0009549
Open

sys-xmlcli wants to merge 1 commit into
intel:mainfrom
sys-xmlcli:PTK0009549

Conversation

@sys-xmlcli

Copy link
Copy Markdown
Contributor

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The security fix lacks a focused regression test covering a zero-length firmware-volume header.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Prevents infinite recursion when parsing malformed zero-length UEFI firmware volumes.

Changes:

  • Rejects firmware-volume headers whose FvLength is zero.
  • Ensures recursive parsing advances through the buffer.
File Description
src/​xmlcli/​common/​bios_fw_parser.py Validates firmware-volume length before parsing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

has_valid_zero_vector = utils.get_integer_value(firmware_volume_header.get_value("ZeroVector")) == 0
if has_valid_signature and has_valid_zero_vector:
# FvLength must be non-zero to guarantee forward progress on the recursive parse walk
has_valid_length = utils.get_integer_value(firmware_volume_header.get_value("FvLength")) > 0

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants