mirror of https://github.com/acidanthera/audk.git
IntelFrameworkModulePkg BootMngr: Fix potential read over memory boundary
This commit will resolve the issue brought by r17737. HelpString = AllocateCopyPool (HelpSize, L"Device Path : "); The above using of AllocateCopyPool() will read contents out of the scope of the constant string. Potential risk for the constant string allocated at the boundary of memory region. Contributed-under: TianoCore Contribution Agreement 1.0 Signed-off-by: Hao Wu <hao.a.wu@intel.com> Reviewed-by: Qiu Shumin <shumin.qiu@intel.com> Reviewed-by: Jeff Fan <jeff.fan@intel.com> git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@17932 6f19259b-4bc3-4df7-8a09-765794883524
This commit is contained in:
parent
a3c9617ea6
commit
577870d560
|
@ -319,8 +319,9 @@ CallBootManager (
|
|||
|
||||
TempStr = DevicePathToStr (Option->DevicePath);
|
||||
HelpSize = StrSize (TempStr) + StrSize (L"Device Path : ");
|
||||
HelpString = AllocateCopyPool (HelpSize, L"Device Path : ");
|
||||
HelpString = AllocateZeroPool (HelpSize);
|
||||
ASSERT (HelpString != NULL);
|
||||
StrCatS (HelpString, HelpSize / sizeof (CHAR16), L"Device Path : ");
|
||||
StrCatS (HelpString, HelpSize / sizeof (CHAR16), TempStr);
|
||||
|
||||
HelpToken = HiiSetString (HiiHandle, 0, HelpString, NULL);
|
||||
|
|
Loading…
Reference in New Issue