From: Johannes Schneider <johannes.schneider@leica-geosystems.com>
To: barebox@lists.infradead.org
Cc: Marco Felsch <m.felsch@pengutronix.de>,
Johannes Schneider <johannes.schneider@leica-geosystems.com>
Subject: [PATCH v1 09/14] efi: loader: authenticode: add a fuzz test
Date: Sun, 4 Oct 2026 01:19:42 +0000 [thread overview]
Message-ID: <20261004011958.3255011-10-johannes.schneider@leica-geosystems.com> (raw)
In-Reply-To: <20261004011958.3255011-1-johannes.schneider@leica-geosystems.com>
authenticode_parse() walks the DER of a PKCS#7 signature taken from the
image before anything about the image is verified. Fuzz it, and the
digest of the signed attributes it hands on, the way the PE parser is
fuzzed.
As EFI_PE_PARSER does for the PE parser, a separate EFI_AUTHENTICODE
builds the verifier without the EFI loader under COMPILE_TEST;
EFI_LOADER_AUTHENTICODE selects it. The libfuzzer configuration enables
it.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Johannes Schneider <johannes.schneider@leica-geosystems.com>
---
common/boards/configs/libfuzzer.config | 1 +
efi/Kconfig | 11 +++++++++++
efi/loader/Kconfig | 2 +-
efi/loader/Makefile | 2 +-
efi/loader/authenticode.c | 13 +++++++++++++
5 files changed, 27 insertions(+), 2 deletions(-)
diff --git a/common/boards/configs/libfuzzer.config b/common/boards/configs/libfuzzer.config
index f0a298559f..40c90d644a 100644
--- a/common/boards/configs/libfuzzer.config
+++ b/common/boards/configs/libfuzzer.config
@@ -16,6 +16,7 @@ CONFIG_DEBUG_MEMLEAK=y
CONFIG_TEST=y
CONFIG_COMPILE_TEST=y
CONFIG_EFI_PE_PARSER=y
+CONFIG_EFI_AUTHENTICODE=y
CONFIG_JWT=y
CONFIG_FUZZ=y
CONFIG_FUZZ_EXTERNAL=y
diff --git a/efi/Kconfig b/efi/Kconfig
index e3f3941831..6c8d6b9de4 100644
--- a/efi/Kconfig
+++ b/efi/Kconfig
@@ -12,6 +12,17 @@ config EFI_PE_PARSER
This can be enabled without the full EFI loader to compile-test and
fuzz PE image parsing.
+config EFI_AUTHENTICODE
+ bool "Authenticode signature verifier" if COMPILE_TEST
+ depends on CRYPTO_BUILTIN_KEYS && HAVE_DIGEST_SHA256
+ select CRYPTO_RSA
+ select EFI_PE_PARSER
+ help
+ Build the Authenticode (PKCS#7) verifier used by the EFI loader.
+
+ This can be enabled without the full EFI loader to compile-test and
+ fuzz the parsing of Authenticode signatures.
+
config EFI_PAYLOAD
bool "barebox as EFI payload/app (consumer)"
depends on HAVE_EFI_PAYLOAD || COMPILE_TEST
diff --git a/efi/loader/Kconfig b/efi/loader/Kconfig
index 4099da0689..8345fccd1a 100644
--- a/efi/loader/Kconfig
+++ b/efi/loader/Kconfig
@@ -27,7 +27,7 @@ config EFI_LOADER_SECURE_BOOT
config EFI_LOADER_AUTHENTICODE
bool "Verify Authenticode signatures of booted EFI images"
depends on CRYPTO_BUILTIN_KEYS && HAVE_DIGEST_SHA256
- select CRYPTO_RSA
+ select EFI_AUTHENTICODE
help
Verify the Authenticode (PKCS#7, SHA-256, RSA) signature of an EFI
image booted with bootm against the keys compiled into the "efi"
diff --git a/efi/loader/Makefile b/efi/loader/Makefile
index 775014dc22..f590fb278a 100644
--- a/efi/loader/Makefile
+++ b/efi/loader/Makefile
@@ -1,6 +1,7 @@
# SPDX-License-Identifier: GPL-2.0
obj-$(CONFIG_EFI_PE_PARSER) += pe.o
+obj-$(CONFIG_EFI_AUTHENTICODE) += authenticode.o
ifeq ($(CONFIG_EFI_LOADER),y)
@@ -14,7 +15,6 @@ obj-y += boot.o
obj-y += runtime.o
obj-y += setup.o
obj-y += watchdog.o
-obj-$(CONFIG_EFI_LOADER_AUTHENTICODE) += authenticode.o
obj-y += loadopts.o
obj-y += efi_var_common.o
obj-y += efi_variable.o
diff --git a/efi/loader/authenticode.c b/efi/loader/authenticode.c
index 36e5a46fc6..ef2ea895e1 100644
--- a/efi/loader/authenticode.c
+++ b/efi/loader/authenticode.c
@@ -15,6 +15,7 @@
#include <efi/loader/authenticode.h>
#include <efi/error.h>
#include <pe.h>
+#include <fuzz.h>
struct der {
const u8 *p;
@@ -340,6 +341,18 @@ static int sha256_attrs(const struct authenticode *a, u8 *out)
return ret;
}
+static int fuzz_authenticode(const u8 *data, size_t size)
+{
+ struct authenticode a = {};
+ u8 hash[SHA256_DIGEST_SIZE];
+
+ if (!authenticode_parse(&a, data, size))
+ sha256_attrs(&a, hash);
+
+ return 0;
+}
+fuzz_test("authenticode", fuzz_authenticode);
+
/**
* efi_authenticode_verify() - verify a PE image's Authenticode signature
* @efi: PE image
--
2.43.0
next prev parent reply other threads:[~2026-10-04 1:25 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 1:19 [PATCH v1 00/14] efi: loader: boot Authenticode-signed UKIs Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 01/14] mfd: hgs-efi: do not claim the name of the EFI loader's device Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 02/14] efi: loader: file: report EFI_UNSUPPORTED for volumes without a filesystem Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 03/14] efi: loader: bootm: free the devicetree after installing it Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 04/14] efi: loader: provide EFI_DT_FIXUP_PROTOCOL Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 05/14] efi: loader: pe: add helpers for the image size and a named section Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 06/14] efi: loader: bootm: load only the PE image, not the whole file Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 07/14] efi: loader: bootm: pass the kernel command line to UKIs Johannes Schneider
2026-10-05 17:18 ` Ahmad Fatoum
2026-10-04 1:19 ` [PATCH v1 08/14] efi: loader: verify Authenticode signatures against built-in keys Johannes Schneider
2026-10-05 5:33 ` Ahmad Fatoum
2026-10-05 5:45 ` SCHNEIDER Johannes
2026-10-09 0:07 ` SCHNEIDER Johannes
2026-10-04 1:19 ` Johannes Schneider [this message]
2026-10-04 1:19 ` [PATCH v1 10/14] efi: loader: authenticate LoadImage() images when signing is forced Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 11/14] efi: loader: file: expose no filesystem when signed images are forced Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 12/14] bootm: efi: boot signed EFI images " Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 13/14] efi: loader: bootm: install a devicetree for matching UKI devicetrees Johannes Schneider
2026-10-04 1:19 ` [PATCH v1 14/14] efi: loader: bootm: apply overlays carried by a UKI Johannes Schneider
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004011958.3255011-10-johannes.schneider@leica-geosystems.com \
--to=johannes.schneider@leica-geosystems.com \
--cc=barebox@lists.infradead.org \
--cc=m.felsch@pengutronix.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox