nccgroup / depthcharge

A U-Boot hacking toolkit for security researchers and tinkerers
https://depthcharge.readthedocs.io
BSD 3-Clause "New" or "Revised" License
257 stars 14 forks source link

Add Checker for part_test_dos stack overflow (no CVE) #98

Closed jynik closed 2 years ago

jynik commented 2 years ago

This vulnerability and its practical exploitation are detailed in this excellent writeup:

https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html

As the author astutely points out...

Regarding the vulnerability itself, it shouldn't even exist since it's already been fixed upstream, twice: