Re: [PATCH] board: amlogic: fix buffler overflow in serial & usid read

Tom Rini <[email protected]>
Newsgroups io.groups.u-boot-amlogic,org.u-boot-project.lists.u-boot
Message-ID <20240320124412.GT3442575@bill-the-cat>
On Wed, Mar 20, 2024 at 09:26:29AM +0100, Neil Armstrong wrote:
> On 20/03/2024 06:28, Dan Carpenter wrote:
> > On Tue, Mar 19, 2024 at 03:53:24PM +0100, Neil Armstrong wrote:
> > > While meson_sm_read_efuse() doesn't overflow, the string is not
> > > zero terminated and env_set() will buffer overflow and add random
> > > characters to environment.
> > > 
> > 
> > In the Linux kernel we would give this a CVE because it's information
> > disclosure bug...
> 
> Yes probably

Yes, but this isn't the Linux kernel and we aren't a CNA. I don't object
to someone getting a CVE if so inclined, but we don't have the resources
to follow in the kernel's footsteps here either.

-- 
Tom
signature.asc (application/pgp-signature, 659 B)
-----BEGIN PGP SIGNATURE-----

iQGzBAABCgAdFiEEGjx/cOCPqxcHgJu/FHw5/5Y0tywFAmX62hwACgkQFHw5/5Y0
tywk6Qv/bn6uXpmVLGwBxdILKZcZRjMR+b0W/BBGOyAdmb2S/Q4pzvjR1Q0MzVe/
Hw3Ej4Y0PV3T96iikx/S+J84nf93uKuHxV5+8Kc8v7dleJ+x5PnmuBE/pAeIEC63
SG8ePTo2klOWZHQieiKcHrFlZwaGp9ccjvjHRJusi8pZH4x/a4BPYojUcoYnpY+j
qeJEDZ0ydncUsBah6I+PgOf56YfrnpEuiGBWZXF/XtMfxblmOeGb1P48kcInZerq
QQmAuyTodVd8Qh9PasI8W+lPzR9hRSZjq96kS7iYh1U3R+tMdkcrtxF82vFBJzKr
96EV3lxaq0A/HPc6nT2mGWoQ6/jOpP9p+6cGgqebimSpxbKmGw5w1TmhVoPA0b4X
BkW8jyPm/M3tVaXcv+a6uj6XBEucle0lgdW0E/b0Dh5e+MGqMzD248YT6+mr6uLY
ig/eke0NWcSunibmICgXrT/C5HS5nN3/xol33dFk0SeSZHBM/IzE8/eXkVSrEgKI
MDIKmLO7
=R/NW
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.