boot: reject GPT headers with SizeOfPartitionEntry below the minimum

Commit 0cf5f816f2 replaced the original lower-bound check

    if (h->SizeOfPartitionEntry < sizeof(EFI_PARTITION_ENTRY))
            return false;

with a multiple-of check

    if ((h->SizeOfPartitionEntry % sizeof(EFI_PARTITION_ENTRY)) != 0)
            return false;

to additionally require the entry size to be a multiple of 128. The
modulo test is however also satisfied by SizeOfPartitionEntry == 0, so a
GPT header advertising a zero entry size now passes verify_gpt().

Restore the lower bound in addition to the multiple-of check, so the
entry size must be at least sizeof(EFI_PARTITION_ENTRY) and a multiple of
it (128 bytes).

Follow-up for 0cf5f816f2
This commit is contained in:
Luca Boccassi
2026-06-26 17:15:38 +01:00
parent d04fbcf956
commit d06d8a232b

View File

@@ -60,7 +60,8 @@ static bool verify_gpt(/* const */ GptHeader *h, EFI_LBA lba_expected) {
if (h->MyLBA != lba_expected)
return false;
if ((h->SizeOfPartitionEntry % sizeof(EFI_PARTITION_ENTRY)) != 0)
if (h->SizeOfPartitionEntry < sizeof(EFI_PARTITION_ENTRY) ||
(h->SizeOfPartitionEntry % sizeof(EFI_PARTITION_ENTRY)) != 0)
return false;
if (h->NumberOfPartitionEntries <= 0 || h->NumberOfPartitionEntries > 1024)