font: Do not load more than one NAME section

The GRUB font file can have one NAME section only. Though if somebody
crafts a broken font file with many NAME sections and loads it then the
GRUB leaks memory. So, prevent against that by loading first NAME
section and failing in controlled way on following one.

Reported-by: Chris Coulson <chris.coulson@canonical.com>
Signed-off-by: Daniel Kiper <daniel.kiper@oracle.com>
Reviewed-by: Jan Setje-Eilers <jan.setjeeilers@oracle.com>
This commit is contained in:
Daniel Kiper 2020-07-07 15:36:26 +02:00
parent 2a1edcf2ed
commit 89f3da1a3d

View file

@ -532,6 +532,12 @@ grub_font_load (const char *filename)
if (grub_memcmp (section.name, FONT_FORMAT_SECTION_NAMES_FONT_NAME, if (grub_memcmp (section.name, FONT_FORMAT_SECTION_NAMES_FONT_NAME,
sizeof (FONT_FORMAT_SECTION_NAMES_FONT_NAME) - 1) == 0) sizeof (FONT_FORMAT_SECTION_NAMES_FONT_NAME) - 1) == 0)
{ {
if (font->name != NULL)
{
grub_error (GRUB_ERR_BAD_FONT, "invalid font file: too many NAME sections");
goto fail;
}
font->name = read_section_as_string (&section); font->name = read_section_as_string (&section);
if (!font->name) if (!font->name)
goto fail; goto fail;