mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
A malicious USB device is out of scope for our threat model, but we already sanity check other descriptor fields, so we should also check that the reported length of a descriptor contained within a USB device configuration is adequate for the claimed descriptor type. Update the two descriptor iterators to skip over descriptors that are shorter than the length required to contain the iterator type, so that the loop body can assume that it is safe to dereference any field within the iterator structure. Simplify the call sites by integrating the descriptor type check into the iterator itself, since it fits very naturally alongside the length check. Guard against infinite loops by ignoring any descriptors with a length field that is too short to contain the descriptor header itself. Validate the descriptor length in usb_endpoint_companion_descriptor(), which is the only standalone use of usb_next_descriptor() outside of the two iterators. Signed-off-by: Michael Brown <mcb30@ipxe.org>