diff options
author | Eric Dong <eric.dong@intel.com> | 2018-07-31 13:13:20 +0800 |
---|---|---|
committer | Eric Dong <eric.dong@intel.com> | 2018-08-01 19:11:00 +0800 |
commit | 87acb6e298e718250dd8b741b6888a3a54c7cb5a (patch) | |
tree | 742f329d651d9f289f770c07b71f5cbe64e78df7 /MdeModulePkg/Bus/Pci/NvmExpressDxe/NvmExpressPassthru.c | |
parent | c4c7fb388e7f86fa98417a706bb495fb3c3c910b (diff) | |
download | edk2-87acb6e298e718250dd8b741b6888a3a54c7cb5a.tar.gz |
SecurityPkg OpalPasswordSupportLib: Add check to avoid potential buffer overflow.
Current code not check the CommunicationBuffer size before use it. Attacker can
read beyond the end of the (untrusted) commbuffer into controlled memory. Attacker
can get access outside of valid SMM memory regions. This patch add check before
use it.
bugz: https://bugzilla.tianocore.org/show_bug.cgi?id=198
Cc: Yao Jiewen <jiewen.yao@intel.com>
Cc: Wu Hao <hao.a.wu@intel.com>
Contributed-under: TianoCore Contribution Agreement 1.0
Signed-off-by: Eric Dong <eric.dong@intel.com>
Reviewed-by: Yao Jiewen <jiewen.yao@intel.com>
Diffstat (limited to 'MdeModulePkg/Bus/Pci/NvmExpressDxe/NvmExpressPassthru.c')
0 files changed, 0 insertions, 0 deletions