tpm_seal() computes storedsize from TPM response fields and passes it directly to memcpy() into a MAX_BLOB_SIZE buffer without bounds validation. A forged TPM response can set storedsize to 4086, overflowing the 512-byte blob by 3574 bytes into adjacent slab objects.
Add a check that storedsize does not exceed MAX_BLOB_SIZE before the memcpy, returning -EINVAL on oversized responses. Signed-off-by: Sanket Sharma <[email protected]> --- security/keys/trusted-keys/trusted_tpm1.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/security/keys/trusted-keys/trusted_tpm1.c b/security/keys/trusted-keys/trusted_tpm1.c index 8f57c6111..d47cb7108 100644 --- a/security/keys/trusted-keys/trusted_tpm1.c +++ b/security/keys/trusted-keys/trusted_tpm1.c @@ -531,6 +531,10 @@ static int tpm_seal(struct tpm_buf *tb, uint16_t keytype, /* copy the returned blob to caller */ if (!ret) { + if (storedsize > MAX_BLOB_SIZE) { + ret = -EINVAL; + goto out; + } memcpy(blob, tb->data + TPM_DATA_OFFSET, storedsize); *bloblen = storedsize; } -- 2.53.0

