Blame SOURCES/0001-tpm2_policy.c-restrict-policy-digest-size.patch

5b830c
From e556da0a2099573f82391c16477fba08584a7a12 Mon Sep 17 00:00:00 2001
5b830c
From: Imran Desai <imran.desai@intel.com>
5b830c
Date: Tue, 10 Mar 2020 09:15:55 -0700
5b830c
Subject: [PATCH] tpm2_policy.c: restrict policy digest size
5b830c
5b830c
Fixes #1916
5b830c
5b830c
Signed-off-by: Imran Desai <imran.desai@intel.com>
5b830c
---
5b830c
 lib/tpm2_policy.c | 2 +-
5b830c
 1 file changed, 1 insertion(+), 1 deletion(-)
5b830c
5b830c
diff --git a/lib/tpm2_policy.c b/lib/tpm2_policy.c
5b830c
index 6c352b2b41ae..01387ba01645 100644
5b830c
--- a/lib/tpm2_policy.c
5b830c
+++ b/lib/tpm2_policy.c
5b830c
@@ -163,7 +163,7 @@ tool_rc tpm2_policy_build_policyauthorize(ESYS_CONTEXT *ectx,
5b830c
     bool result = true;
5b830c
     TPM2B_DIGEST approved_policy = { .size = 0 };
5b830c
     if (policy_digest_path) {
5b830c
-        approved_policy.size = UINT16_MAX;
5b830c
+        approved_policy.size = sizeof(TPMU_HA);
5b830c
         result = files_load_bytes_from_path(policy_digest_path,
5b830c
             approved_policy.buffer, &approved_policy.size);
5b830c
     }
5b830c
-- 
5b830c
2.31.0
5b830c