]> git.proxmox.com Git - mirror_edk2.git/commit
UefiCpuPkg/SecMigrationPei: Add initial PEIM (CVE-2019-11098)
authorMichael Kubacki <michael.a.kubacki@intel.com>
Sun, 21 Apr 2019 21:21:55 +0000 (14:21 -0700)
committermergify[bot] <37929162+mergify[bot]@users.noreply.github.com>
Tue, 28 Jul 2020 01:43:16 +0000 (01:43 +0000)
commit479613bd06546e30652354d5dd76ee7b377fb92c
tree01862963a61900656e0c14fa242515ca113eb7aa
parent60b12e69fb1c8c7180fdda92f008248b9ec83db1
UefiCpuPkg/SecMigrationPei: Add initial PEIM (CVE-2019-11098)

REF:https://bugzilla.tianocore.org/show_bug.cgi?id=1614

Adds a PEIM that republishes structures produced in SEC. This
is done because SEC modules may not be shadowed in some platforms
due to space constraints or special alignment requirements. The
SecMigrationPei module locates interfaces that may be published in
SEC and reinstalls the interface with permanent memory addresses.

This is important if pre-memory address access is forbidden after
memory initialization and data such as a PPI descriptor, PPI GUID,
or PPI inteface reside in pre-memory.

Cc: Eric Dong <eric.dong@intel.com>
Cc: Ray Ni <ray.ni@intel.com>
Cc: Laszlo Ersek <lersek@redhat.com>
Cc: Rahul Kumar <rahul1.kumar@intel.com>
Cc: Debkumar De <debkumar.de@intel.com>
Cc: Harry Han <harry.han@intel.com>
Cc: Catharine West <catharine.west@intel.com>
Signed-off-by: Michael Kubacki <michael.a.kubacki@intel.com>
Acked-by: Laszlo Ersek <lersek@redhat.com>
Reviewed-by: Liming Gao <liming.gao@intel.com>
UefiCpuPkg/Include/Ppi/RepublishSecPpi.h [new file with mode: 0644]
UefiCpuPkg/SecCore/SecCore.inf
UefiCpuPkg/SecCore/SecMain.c
UefiCpuPkg/SecCore/SecMain.h
UefiCpuPkg/SecMigrationPei/SecMigrationPei.c [new file with mode: 0644]
UefiCpuPkg/SecMigrationPei/SecMigrationPei.h [new file with mode: 0644]
UefiCpuPkg/SecMigrationPei/SecMigrationPei.inf [new file with mode: 0644]
UefiCpuPkg/SecMigrationPei/SecMigrationPei.uni [new file with mode: 0644]
UefiCpuPkg/UefiCpuPkg.dec
UefiCpuPkg/UefiCpuPkg.dsc