| From stable+bounces-227634-greg=kroah.com@vger.kernel.org Fri Mar 20 22:55:34 2026 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Fri, 20 Mar 2026 17:55:26 -0400 |
| Subject: mtd: Avoid boot crash in RedBoot partition table parser |
| To: stable@vger.kernel.org |
| Cc: Finn Thain <fthain@linux-m68k.org>, Kees Cook <kees@kernel.org>, linux-hardening@vger.kernel.org, Miquel Raynal <miquel.raynal@bootlin.com>, Sasha Levin <sashal@kernel.org> |
| Message-ID: <20260320215526.133494-2-sashal@kernel.org> |
| |
| From: Finn Thain <fthain@linux-m68k.org> |
| |
| [ Upstream commit 8e2f8020270af7777d49c2e7132260983e4fc566 ] |
| |
| Given CONFIG_FORTIFY_SOURCE=y and a recent compiler, |
| commit 439a1bcac648 ("fortify: Use __builtin_dynamic_object_size() when |
| available") produces the warning below and an oops. |
| |
| Searching for RedBoot partition table in 50000000.flash at offset 0x7e0000 |
| ------------[ cut here ]------------ |
| WARNING: lib/string_helpers.c:1035 at 0xc029e04c, CPU#0: swapper/0/1 |
| memcmp: detected buffer overflow: 15 byte read of buffer size 14 |
| Modules linked in: |
| CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.19.0 #1 NONE |
| |
| As Kees said, "'names' is pointing to the final 'namelen' many bytes |
| of the allocation ... 'namelen' could be basically any length at all. |
| This fortify warning looks legit to me -- this code used to be reading |
| beyond the end of the allocation." |
| |
| Since the size of the dynamic allocation is calculated with strlen() |
| we can use strcmp() instead of memcmp() and remain within bounds. |
| |
| Cc: Kees Cook <kees@kernel.org> |
| Cc: stable@vger.kernel.org |
| Cc: linux-hardening@vger.kernel.org |
| Link: https://lore.kernel.org/all/202602151911.AD092DFFCD@keescook/ |
| Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") |
| Suggested-by: Kees Cook <kees@kernel.org> |
| Signed-off-by: Finn Thain <fthain@linux-m68k.org> |
| Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/mtd/parsers/redboot.c | 6 +++--- |
| 1 file changed, 3 insertions(+), 3 deletions(-) |
| |
| --- a/drivers/mtd/parsers/redboot.c |
| +++ b/drivers/mtd/parsers/redboot.c |
| @@ -270,9 +270,9 @@ nogood: |
| |
| strcpy(names, fl->img->name); |
| #ifdef CONFIG_MTD_REDBOOT_PARTS_READONLY |
| - if (!memcmp(names, "RedBoot", 8) || |
| - !memcmp(names, "RedBoot config", 15) || |
| - !memcmp(names, "FIS directory", 14)) { |
| + if (!strcmp(names, "RedBoot") || |
| + !strcmp(names, "RedBoot config") || |
| + !strcmp(names, "FIS directory")) { |
| parts[i].mask_flags = MTD_WRITEABLE; |
| } |
| #endif |