From: Sriram Sriram <sriramsriram@linux.microsoft.com>
To: u-boot@lists.u-boot-project.org
Cc: Michal Simek <michal.simek@amd.com>,
Tom Rini <trini@konsulko.com>,
Drew Kluemke <ankluemk@microsoft.com>,
Sriram Sriram <sriramsriram@linux.microsoft.com>
Subject: [PATCH 0/2] board: xilinx: Fix board name overflow and allow board ft_board_setup()
Date: Wed, 9 Sep 2026 12:20:45 -0700 [thread overview]
Message-ID: <20260909192047.217421-1-sriramsriram@linux.microsoft.com> (raw)
Two independent fixes to the xilinx vendor common board file, both found
while bringing a downstream Versal NET board up to date with mainline.
Patch 1 fixes a heap buffer overflow in board_name_decode(). The name is
built with strcat() into a 50 byte allocation, and the length check that
is supposed to catch the overflow only runs after the writes. Each EEPROM
descriptor can contribute up to 29 characters, so a base board plus a
carrier card already overruns the buffer with EEPROM-supplied data.
Patch 2 marks ft_board_setup() __weak so that a board using the xilinx
vendor common library can supply its own device tree fixups, the same way
the file already allows board_name_decode(), board_detection(),
soc_detection() and board_rng_seed() to be overridden. Today such a board
fails to link with "multiple definition of ft_board_setup".
Both patches were build tested on xilinx_zynqmp_kria_defconfig, which
enables CONFIG_DTB_RESELECT and CONFIG_OF_BOARD_SETUP and so compiles
both of the changed functions.
Drew Kluemke (1):
board: xilinx: Use strlcat() in board_name_decode()
Sriram Sriram (1):
board: xilinx: Make ft_board_setup() weak
board/xilinx/common/board.c | 22 +++++++++++++---------
1 file changed, 13 insertions(+), 9 deletions(-)
--
2.49.0
next reply other threads:[~2026-09-09 20:45 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 19:20 Sriram Sriram [this message]
2026-09-09 19:20 ` [PATCH 1/2] board: xilinx: Use strlcat() in board_name_decode() Sriram Sriram
2026-09-10 7:56 ` Maarten Brock
2026-09-10 7:59 ` Michal Simek
2026-09-10 8:03 ` Michal Simek
2026-09-10 9:30 ` Maarten Brock
2026-09-10 9:43 ` Michal Simek
2026-09-15 19:24 ` Sriram Sriram
2026-09-16 8:06 ` Michal Simek
2026-09-09 19:20 ` [PATCH 2/2] board: xilinx: Make ft_board_setup() weak Sriram Sriram
2026-09-16 17:36 ` [PATCH v2 0/2] board: xilinx: board_name_decode() allocation fix and weak ft_board_setup() Sriram Sriram
2026-09-16 17:36 ` [PATCH v2 1/2] board: xilinx: Check calloc() result in board_name_decode() Sriram Sriram
2026-09-16 17:36 ` [PATCH v2 2/2] board: xilinx: Make ft_board_setup() weak Sriram Sriram
2026-09-25 13:51 ` [PATCH v2 0/2] board: xilinx: board_name_decode() allocation fix and weak ft_board_setup() Michal Simek
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909192047.217421-1-sriramsriram@linux.microsoft.com \
--to=sriramsriram@linux.microsoft.com \
--cc=ankluemk@microsoft.com \
--cc=michal.simek@amd.com \
--cc=trini@konsulko.com \
--cc=u-boot@lists.u-boot-project.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.