Re: [security] Report of possible heap overflow in U-Boot's Android bootmeth before any AVB verification (ANT-2026-ZWED60S8)
Simon Glass <[email protected]> Thu, 6 Aug 2026 08:52:57 -0600
| Newsgroups | gmane.comp.boot-loaders.u-boot |
|---|---|
| Message-ID | <CAFLszTjWPVBmqtSyOTBG-5qQ+xCmJ+w=vwoX2jUepEvFnZMtAg__29351.4610546239$1786028009$gmane$org@mail.gmail.com> |
Hi Arthur, On Thu, 6 Aug 2026 at 06:23, Arthur Chan <[email protected]> wrote: > > Hello U-Boot maintainers, > > I'd like to report a High-severity security issue in U-Boot (https://github.com/u-boot/u-boot / https://git.u-boot-project.org/u-boot/u-boot) related to possible heap overflow in U-Boot's Android bootmeth before any AVB verification. Thanks for the report. > > I have attached 3 files with this email as described below. > 1) report.md: A full description of the vulnerability and how to reproduce it, together with suggested fix of the issue. > 2) Dockerfile: A Dockerfile for demonstrating the issue. > 3) driver.c: Work with the Dockerfile to demonstrate the issue. > > Attribution > ----------- > Please attribute Claude and Ada Logics. This issue was found by Anthropic from using agents to study security of open source projects, and I am from Ada Logics helping validate the found issues and creating the report manually and notify the maintainers. If this is a standard text, I suggest '...issues found, manually create a report and notify...'. Are you able to send a patch? Then your attribution will be in the source tree :-) Also I suggest avoiding HTML in email to the mailing list. > > Disclosure > ---------- > This report follows a 90-day coordinated disclosure deadline. I'm happy to coordinate on the exact timing and to provide any further detail you need. > > Kind regards, > Arthur Chan > > > > ADA Logics Ltd is registered in England. No: 11624074. > Registered office: 266 Banbury Road, Post Box 292, > OX2 7DL, Oxford, Oxfordshire , United Kingdom Regards, Simon