Michael Brown 21d972d741 [crypto] Check length before decrypting data
Using a CBC-mode cipher with a length that is not a multiple of the
block size will cause an uncontrollable out-of-bounds write of the
entire address space, resulting in a guaranteed crash.  There is no
way to cause the CBC cipher to return before overwriting the entire
address space with pseudorandom data, and so this could only be used
as a denial-of-service attack.

Almost all cipher call sites already validate the length against the
block size.  Add the relevant checks to the two call sites that do not
already do so.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
2026-09-22 12:10:48 +01:00
2026-08-06 12:47:53 +01:00
2026-03-06 15:48:55 +00:00
2026-08-06 12:47:53 +01:00
2015-02-26 17:59:53 +00:00
2026-08-06 00:01:56 +01:00

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.

S
Description
No description provided
Readme
121 MiB
Languages
C 98.5%
Assembly 0.6%
Python 0.3%
Perl 0.3%
Makefile 0.2%