Re: [PATCH v3 3/4] spl: fit: Harden external-data offset and size arithmetic

Tom Rini <[email protected]>
Newsgroups org.u-boot-project.lists.u-boot
Message-ID <20260824213415.GA691042@bill-the-cat>
On Mon, Aug 10, 2026 at 11:09:56PM +0100, Anton Ivanov via U-Boot wrote:

> The data-offset, data-position and data-size FIT properties are
> excluded from the configuration signature, so they are attacker
> controlled even when signature verification succeeds. The offset and
> size arithmetic in load_simple_fit() can wrap on hostile values:
> 
>  - adding the external-data base offset to data-offset can wrap past
>    UINT32_MAX,
>  - get_aligned_image_size() adds the block-alignment overhead and
>    rounds up to the block length, which can wrap past ULONG_MAX,
>  - adding the FIT's device offset to the aligned external-data offset
>    can wrap past ULONG_MAX.
> 
> Make get_aligned_image_size() return the aligned size through an out
> parameter and fail with -EOVERFLOW when the computation would wrap,
> check the two offset additions explicitly, and compare the
> block-aligned size (the amount info->read() actually transfers)
> against max_size before reading. Do the same for the FIT header read
> in spl_simple_fit_read().
> 
> Signed-off-by: Anton Ivanov <[email protected]>

Unfortunately this leads to a large size increase in SPL on am335x_evm
(and related build variants) and it overflows the allowed size.

-- 
Tom
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQTzzqh0PWDgGS+bTHor4qD1Cr/kCgUCaoy41AAKCRAr4qD1Cr/k
Cg8fAP4pYXDTGpNCPI7dJ8W63ZTB3s3O2qS24rGtJA0O2VVQdQEAwmYjGfp3bwI8
KQMpfVzdXBgT/zEApspWLjiJsHMddgQ=
=KfHn
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.