Re: [security] Report of possible arbitrary memory overwrite in U-Boot's EFI PE/COFF loader (ANT-2026-1K18JRMA)

Tom Rini <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot
Message-ID <20260806211500.GA180789__10344.8920812056$1786050927$gmane$org@bill-the-cat>
On Wed, Aug 05, 2026 at 08:43:59PM +0100, Arthur Chan wrote:

> Hello U-Boot (EFI Loader) maintainers,
> 
> I'd like to report a High-severity security issue in  U-Boot (EFI Loader) (https://github.com/u-boot/u-boot / https://git.u-boot-project.org/u-boot/u-boot) related to possible arbitrary memory overwrite in U-Boot's EFI PE/COFF loader.
> 
> I have attached 3 files with this email as described below.
> 1) report.md: A full description of the vulnerability and how to reproduce it, together with suggested fix of the issue.
> 2) Dockerfile: A Dockerfile for demonstrating the issue.
> 3) driver.c: Work with the Dockerfile to demonstrate the issue.
> 
> Attribution
> -----------
> Please attribute Claude and Ada Logics. This issue was found by Anthropic from using agents to study security of open source projects, and I am from Ada Logics helping validate the found issues and creating the report manually and notify the maintainers.
> 
> Disclosure
> ----------
> This report follows a 90-day coordinated disclosure deadline. I'm happy to coordinate on the exact timing and to provide any further detail you need.

So, this applies to all of the reports you've been generating. I want to
point again at
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=36d49bba19f2c19c933d13b25dcf4eb607a030b3
because these reports I believe fail most of the guidelines there. And
in short, addressing issues (and following
https://docs.u-boot.org/en/latest/develop/sending_patches.html) is much
more valuable than just passing on reports. Thanks.

-- 
Tom
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQTzzqh0PWDgGS+bTHor4qD1Cr/kCgUCanT5UAAKCRAr4qD1Cr/k
Ci1iAQDdK7ZSmCOb83PM+H4123aWqFrxGFCf8DBnhQNsUxpWLQD/ZouEWERVHQlg
DRtPpLMnhOfKItDLpfiPVKRWRx//dgI=
=Qsqb
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.