From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [216.205.24.124]) by mx.groups.io with SMTP id smtpd.web11.7725.1605783263152631865 for ; Thu, 19 Nov 2020 02:54:23 -0800 Authentication-Results: mx.groups.io; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=Hk5asip/; spf=pass (domain: redhat.com, ip: 216.205.24.124, mailfrom: lersek@redhat.com) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1605783262; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=25PivCx3eaxZhOUBuu++qg7tu/hqCIEiCuihF2N3ABM=; b=Hk5asip/wA/dMeHbh92jYDigThxKi3mvUhpmNDTo0KYnQHHaORc6sdv3TSxUi5VY24x/rn W6FnqdfezNuyMQgdyBzzUOHZWMqX5UdrR/UpkE+tsfGtHplo5/XAS+Erz1Qd6kjz/8lByC nqziabr/bNxqkoPC8yccF43C41y0lBI= Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-465-Wh489F-FOK-BrHtfzU99Dg-1; Thu, 19 Nov 2020 05:54:14 -0500 X-MC-Unique: Wh489F-FOK-BrHtfzU99Dg-1 Received: from smtp.corp.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id 6096F8EEA8C; Thu, 19 Nov 2020 10:53:43 +0000 (UTC) Received: from lacos-laptop-7.usersys.redhat.com (ovpn-112-236.ams2.redhat.com [10.36.112.236]) by smtp.corp.redhat.com (Postfix) with ESMTP id A675960636; Thu, 19 Nov 2020 10:53:41 +0000 (UTC) From: "Laszlo Ersek" To: edk2-devel-groups-io Cc: Dandan Bi , Hao A Wu , Jian J Wang , Liming Gao , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PATCH v2 RESEND 0/2] security fix: unlimited FV recursion, round 2 (DXE Core) Date: Thu, 19 Nov 2020 11:53:38 +0100 Message-Id: <20201119105340.16225-1-lersek@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.11 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=lersek@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: base64 UmVwbzogICBodHRwczovL3BhZ3VyZS5pby9sZXJzZWsvZWRrMi5naXQKQnJhbmNoOiB0aWFub2Nv cmVfMTc0M192Ml9yZXNlbmQKUmVmOiAgICBodHRwczovL2J1Z3ppbGxhLnRpYW5vY29yZS5vcmcv c2hvd19idWcuY2dpP2lkPTE3NDMKCiJSRVNFTkQiIGJlY2F1c2UgSSdtIHB1YmxpY2x5IHBvc3Rp bmcgdGhlIHBhdGNoZXMgZnJvbQo8aHR0cHM6Ly9idWd6aWxsYS50aWFub2NvcmUub3JnL3Nob3df YnVnLmNnaT9pZD0xNzQzI2MxOT4uCgpUaGUgUmV2aWV3ZWQtYnkgdGFncyBvbiB0aGUgcGF0Y2hl cyBvcmlnaW5hdGUgZnJvbQo8aHR0cHM6Ly9idWd6aWxsYS50aWFub2NvcmUub3JnL3Nob3dfYnVn LmNnaT9pZD0xNzQzI2MyMD4gYW5kCjxodHRwczovL2J1Z3ppbGxhLnRpYW5vY29yZS5vcmcvc2hv d19idWcuY2dpP2lkPTE3NDMjYzIyPi4KClJldGVzdGVkIHdpdGggTGltaW5nJ3MgcmVwcm9kdWNl cjsgc2VlCjxodHRwczovL2J1Z3ppbGxhLnRpYW5vY29yZS5vcmcvc2hvd19idWcuY2dpP2lkPTE3 NDMjYzE2PiBhbmQKPGh0dHBzOi8vYnVnemlsbGEudGlhbm9jb3JlLm9yZy9zaG93X2J1Zy5jZ2k/ aWQ9MTc0MyNjMTg+LgoKVGhpcyBzZXJpZXMgdGFyZ2V0cyBlZGsyLXN0YWJsZTIwMjAxMS4gSSBw bGFuIHRvIG1lcmdlIGl0IGxhdGVyIHRoaXMKd2VlaywgYmFzZWQgb24gTGltaW5nJ3MgUi1iLgoK TGltaW5nLCBoaWdobGlnaHRpbmcgVGlhbm9Db3JlIzE3NDMgaW4gdGhlICJwcm9wb3NlZCBmZWF0 dXJlcyIgbGlzdApjb3VsZCBiZSB1c2VmdWwuCgpDYzogRGFuZGFuIEJpIDxkYW5kYW4uYmlAaW50 ZWwuY29tPgpDYzogSGFvIEEgV3UgPGhhby5hLnd1QGludGVsLmNvbT4KQ2M6IEppYW4gSiBXYW5n IDxqaWFuLmoud2FuZ0BpbnRlbC5jb20+CkNjOiBMaW1pbmcgR2FvIDxnYW9saW1pbmdAYnlvc29m dC5jb20uY24+CkNjOiBQaGlsaXBwZSBNYXRoaWV1LURhdWTDqSA8cGhpbG1kQHJlZGhhdC5jb20+ CgpUaGFua3MhCkxhc3psbwoKTGFzemxvIEVyc2VrICgyKToKICBNZGVNb2R1bGVQa2cvQ29yZS9E eGU6IGFzc2VydCBTZWN0aW9uSW5zdGFuY2UgaW52YXJpYW50IGluCiAgICBGaW5kQ2hpbGROb2Rl KCkKICBNZGVNb2R1bGVQa2cvQ29yZS9EeGU6IGxpbWl0IEZ3Vm9sIGVuY2Fwc3VsYXRpb24gc2Vj dGlvbiByZWN1cnNpb24KCiBNZGVNb2R1bGVQa2cvTWRlTW9kdWxlUGtnLmRlYyAgICAgICAgICAg ICAgICAgICAgICAgICAgICAgICAgICAgfCAgNiArKysKIE1kZU1vZHVsZVBrZy9NZGVNb2R1bGVQ a2cudW5pICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICB8ICA2ICsrKwogTWRlTW9k dWxlUGtnL0NvcmUvRHhlL0R4ZU1haW4uaW5mICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg IHwgIDEgKwogTWRlTW9kdWxlUGtnL0NvcmUvRHhlL1NlY3Rpb25FeHRyYWN0aW9uL0NvcmVTZWN0 aW9uRXh0cmFjdGlvbi5jIHwgNTIgKysrKysrKysrKysrKysrKystLS0KIDQgZmlsZXMgY2hhbmdl ZCwgNTkgaW5zZXJ0aW9ucygrKSwgNiBkZWxldGlvbnMoLSkKCi0tIAoyLjE5LjEuMy5nMzAyNDdh YTVkMjAxCgo=