[usb] Guard against invalid descriptor lengths in USB configurations

A malicious USB device is out of scope for our threat model, but we
already sanity check other descriptor fields, so we should also check
that the reported length of a descriptor contained within a USB device
configuration is adequate for the claimed descriptor type.

Update the two descriptor iterators to skip over descriptors that are
shorter than the length required to contain the iterator type, so that
the loop body can assume that it is safe to dereference any field
within the iterator structure.  Simplify the call sites by integrating
the descriptor type check into the iterator itself, since it fits very
naturally alongside the length check.

Guard against infinite loops by ignoring any descriptors with a length
field that is too short to contain the descriptor header itself.

Validate the descriptor length in usb_endpoint_companion_descriptor(),
which is the only standalone use of usb_next_descriptor() outside of
the two iterators.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
6 files changed
tree: 6e1dbc0a22ecc85e5b05d503fcb847101f78f383
  1. .claude/
  2. .github/
  3. contrib/
  4. src/
  5. AGENTS.md
  6. CHANGELOG.md
  7. CLAUDE.md
  8. CONTRIBUTING.md
  9. COPYING
  10. COPYING.GPLv2
  11. COPYING.UBDL
  12. README.md
  13. RELEASE.md
  14. RELNOTES.tmpl.md
  15. SECURITY.md
README.md

iPXE network bootloader

Build Coverity Release

iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:

  • boot from a web server via HTTP or HTTPS,

  • boot from an iSCSI, FCoE, or AoE SAN,

  • control the boot process with a script,

  • create interactive forms and menus.

You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.

iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).

You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.

For full documentation, visit the iPXE website.