All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] bootstage: fix unchecked malloc and undersized buffer in bootstage_mark_code()
@ 2026-09-01 10:23 Naveen Kumar Chaudhary
  2026-09-01 13:47 ` Simon Glass
  0 siblings, 1 reply; 5+ messages in thread
From: Naveen Kumar Chaudhary @ 2026-09-01 10:23 UTC (permalink / raw)
  To: trini; +Cc: u-boot

bootstage_mark_code() allocated the label buffer without checking the
result and then dereferenced it, risking a NULL pointer crash on
allocation failure. The length calculation also failed to account for
the "," and ": " separators emitted by the snprintf() calls, so the
assembled string could be silently truncated. Additionally, when file
and func are NULL and linenum is -1, the buffer was passed on
uninitialized.

Account for the separator bytes, bail out on allocation failure, and
ensure the buffer is always NUL-terminated.

Signed-off-by: Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
---
 common/bootstage.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

diff --git a/common/bootstage.c b/common/bootstage.c
index 4532100acea..9e1a8609148 100644
--- a/common/bootstage.c
+++ b/common/bootstage.c
@@ -175,12 +175,15 @@ ulong bootstage_mark_code(const char *file, const char *func, int linenum)
 	if (linenum != -1)
 		len = 11;
 	if (func)
-		len += strlen(func);
+		len += strlen(func) + 2;	/* ": " separator */
 	if (file)
-		len += strlen(file);
+		len += strlen(file) + 1;	/* "," separator */
 
 	str = malloc(len + 1);
+	if (!str)
+		return timer_get_boot_us();
 	p = str;
+	*p = '\0';
 	end = p + len;
 	if (file)
 		p += snprintf(p, end - p, "%s,", file);
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-02 16:31 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-01 10:23 [PATCH] bootstage: fix unchecked malloc and undersized buffer in bootstage_mark_code() Naveen Kumar Chaudhary
2026-09-01 13:47 ` Simon Glass
2026-09-01 14:03   ` Tom Rini
2026-09-02 12:29     ` Simon Glass
2026-09-02 16:31       ` Tom Rini

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.