From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) by mx.groups.io with SMTP id smtpd.web10.5246.1664351368819791623 for ; Wed, 28 Sep 2022 00:49:28 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@google.com header.s=20210112 header.b=PT3DsW+O; spf=pass (domain: flex--yuanyu.bounces.google.com, ip: 209.85.214.201, mailfrom: 3h_wzywykbxamiobmiuccuzs.qcarsjszsryq.ufcidg.wc@flex--yuanyu.bounces.google.com) Received: by mail-pl1-f201.google.com with SMTP id b11-20020a170902d50b00b0017828988079so7889420plg.21 for ; Wed, 28 Sep 2022 00:49:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date; bh=jo2LQl6xcKbvAXGCE3JEGA9F8mif7ncqbHkTY4UACww=; b=PT3DsW+OJOnTv91yyuCqZdYVsKdAcaW/zWrgSkczbOGRfGQfa4EuM9kjO0WkRphiS9 hKpiEWRAvmQn61DcMJ5CsOC6+e8S5CwNJsUGfmnb0vt/mx8V5H17tD2oW+waEBsIK5wP Gx6VufPlQRSKc1gv5VL2fSleX30I7Mg3NYUuMgaJ5j2LmtZ467go2vIJQpUf2yiBBCX1 CunB6RjFrPqcW9NIk5gI/CfDT/NIfjeVSwM5o3E5l0yhummrEE+UUXEswU//aSkDgv4N Uzueoha+GfC9PTa1j//vx5KVaRyoZTU0fYKqh0PsCmjQObD/i6tzP0E0b8d6/+F9JhXD UaLQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date; bh=jo2LQl6xcKbvAXGCE3JEGA9F8mif7ncqbHkTY4UACww=; b=TPKnOXQA5/jckWDKjV8lJWjHeaUczizmEgznlriwQC7brgnbY1ah32s9Og/2BeuhTj MNc3UlbfZiObVibKPM9zJkBOBcpLT6dYFJb+fLNpdBtH942k5iiDekspnqvWi46xFVqa iLMxNqOAUBuJ2yFmeTuzL8WYGNbbRPFCj/V/afTeXIyCi7seImystKNH9Vv0s5QR1vtH 7GUCMfeaq1pbOFqrT6QsPsKyy0jq5k7wIn4x38bHgGbNFXVNTNJTyqDuJnj6fHlvWl4c cvjKhWEXphu5/ihWYJEAe5y2dKmK+PJAuTCJK9tM6eda1h3haUmnRDzC41FPnIQXKsSZ R5Yg== X-Gm-Message-State: ACrzQf2ssddT5BQs/PL5p+06wei415iTnM1UEV9LgeBfz0fzAdZnGs9e pOJ/wGM+TxnsGiJNpwkxy6FTc4m45W4SvfqzvFVZoBCtiukzchPhB+vrXD92NwPZFi8B7Y3IP4A dDcaRAAmvvN9gd+nEJAprn70L2kcdSABTxc6HSV9yFZHDnqQYufMLVbVsEwk= X-Google-Smtp-Source: AMsMyM77jB1k49w2hZfKelOK1iVZ0JqPm71brjrVU3xUb2z8fAHrLiO5JZvxOdXJzRvQ/ChozgCuWYOlACg= X-Received: from yuanyu.kir.corp.google.com ([2620:15c:29:204:723d:1dc4:5886:3bcf]) (user=yuanyu job=sendgmr) by 2002:a17:90a:cd06:b0:203:ae0e:6a21 with SMTP id d6-20020a17090acd0600b00203ae0e6a21mr557397pju.0.1664351367522; Wed, 28 Sep 2022 00:49:27 -0700 (PDT) Date: Wed, 28 Sep 2022 00:49:24 -0700 In-Reply-To: <20220928074924.528583-1-yuanyu@google.com> Mime-Version: 1.0 References: <20220928074924.528583-1-yuanyu@google.com> X-Mailer: git-send-email 2.37.3.998.g577e59143f-goog Message-ID: <20220928074924.528583-2-yuanyu@google.com> Subject: [PATCH v1 1/1] CryptoPkg: Fix integer overflow From: "Yuan Yu" To: devel@edk2.groups.io Cc: Ard Biesheuvel , Jordan Justen , Laszlo Ersek , Anthony Perard , Julien Grall Content-Type: text/plain; charset="UTF-8" SECSPERDAY is 86400 which exceeds the limit of a UINT16 which is 65536. Therefore DayRemainder cannot use UINT16. This patch makes it UINT32. Cc: Ard Biesheuvel Cc: Jordan Justen Cc: Laszlo Ersek Cc: Anthony Perard Cc: Julien Grall Signed-off-by: Yuan Yu --- CryptoPkg/Library/BaseCryptLib/SysCall/TimerWrapper.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CryptoPkg/Library/BaseCryptLib/SysCall/TimerWrapper.c b/CryptoPkg/Library/BaseCryptLib/SysCall/TimerWrapper.c index 7d28446d4b5c..bf8a5325817f 100644 --- a/CryptoPkg/Library/BaseCryptLib/SysCall/TimerWrapper.c +++ b/CryptoPkg/Library/BaseCryptLib/SysCall/TimerWrapper.c @@ -118,7 +118,7 @@ gmtime ( { struct tm *GmTime; UINT16 DayNo; - UINT16 DayRemainder; + UINT32 DayRemainder; time_t Year; time_t YearNo; UINT16 TotalDays; @@ -136,7 +136,7 @@ gmtime ( ZeroMem ((VOID *)GmTime, (UINTN)sizeof (struct tm)); DayNo = (UINT16)(*timer / SECSPERDAY); - DayRemainder = (UINT16)(*timer % SECSPERDAY); + DayRemainder = (UINT32)(*timer % SECSPERDAY); GmTime->tm_sec = (int)(DayRemainder % SECSPERMIN); GmTime->tm_min = (int)((DayRemainder % SECSPERHOUR) / SECSPERMIN); -- 2.37.3.998.g577e59143f-goog