Re: [security] Report of possible heap overflow in U-Boot EFI TCG2 boot loader (ANT-2026-CBSBSFG8)

Heinrich Schuchardt <[email protected]>
Newsgroups gmane.comp.boot-loaders.u-boot
Message-ID <cf0dc62c-6914-45cb-91de-7bfc9b592d05__24257.4716381327$1786989954$gmane$org@gmx.de>
On 8/6/26 14:18, Arthur Chan wrote:
> Hello U-Boot maintainers,
> 
> I'd like to report a High-severity security issue in  U-Boot (https:// 
> github.com/u-boot/u-boot / https://git.u-boot-project.org/u-boot/u-boot) 
> related to possible heap overflow in U-Boot EFI TCG2 boot loader.
> 
> I have attached 3 files with this email as described below.
> 1) report.md: A full description of the vulnerability and how to 
> reproduce it, together with suggested fix of the issue.
> 2) Dockerfile: A Dockerfile for demonstrating the issue.
> 3) driver.c: Work with the Dockerfile to demonstrate the issue.

@Ilias

alloc_read_gpt_entries() on 32bit systems seems to have the same issue.

I guess we should correct the code in disk/part_efi.c first and then 
reuse it for the TCG2 protocol driver.

Best regards

Heinrich

> 
> Attribution
> *-----------*
> Please attribute Claude and Ada Logics. This issue was found by 
> Anthropic from using agents to study security of open source projects, 
> and I am from Ada Logics helping validate the found issues and creating 
> the report manually and notify the maintainers.
> 
> Disclosure
> *----------*
> This report follows a 90-day coordinated disclosure deadline. I'm happy 
> to coordinate on the exact timing and to provide any further detail you 
> need.
> 
> Kind regards,
> Arthur Chan
> 
> 
> 
> ADA Logics Ltd is registered in England. No: 11624074.
> Registered office: 266 Banbury Road, Post Box 292,
> OX2 7DL, Oxford, Oxfordshire , United Kingdom
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.