From: Mattijs Korpershoek <mkorpershoek@kernel.org>
To: Simon Glass <sjg@chromium.org>, Arthur Chan <arthur.chan@adalogics.com>
Cc: u-boot@lists.u-boot-project.org,
David Korczynski <david@adalogics.com>,
Adam Korczynski <adam@adalogics.com>,
"security-cvd@anthropic.com" <security-cvd@anthropic.com>,
trini@konsulko.com, mkorpershoek@kernel.org
Subject: Re: [security] Report of possible heap overflow in U-Boot's Android bootmeth before any AVB verification (ANT-2026-ZWED60S8)
Date: Tue, 11 Aug 2026 14:39:27 +0200 [thread overview]
Message-ID: <871pc43k74.fsf@kernel.org> (raw)
In-Reply-To: <CAFLszTjWPVBmqtSyOTBG-5qQ+xCmJ+w=vwoX2jUepEvFnZMtAg@mail.gmail.com>
Hi Arthur,
Thank you for the report.
On Thu, Aug 06, 2026 at 08:52, Simon Glass <sjg@chromium.org> wrote:
> Hi Arthur,
>
> On Thu, 6 Aug 2026 at 06:23, Arthur Chan <arthur.chan@adalogics.com> wrote:
>>
>> Hello U-Boot maintainers,
>>
>> I'd like to report a High-severity security issue in U-Boot (https://github.com/u-boot/u-boot / https://git.u-boot-project.org/u-boot/u-boot) related to possible heap overflow in U-Boot's Android bootmeth before any AVB verification.
>
> Thanks for the report.
>
>>
>> I have attached 3 files with this email as described below.
>> 1) report.md: A full description of the vulnerability and how to reproduce it, together with suggested fix of the issue.
>> 2) Dockerfile: A Dockerfile for demonstrating the issue.
>> 3) driver.c: Work with the Dockerfile to demonstrate the issue.
>>
>> Attribution
>> -----------
>> Please attribute Claude and Ada Logics. This issue was found by Anthropic from using agents to study security of open source projects, and I am from Ada Logics helping validate the found issues and creating the report manually and notify the maintainers.
>
> If this is a standard text, I suggest '...issues found, manually
> create a report and notify...'.
>
> Are you able to send a patch? Then your attribution will be in the
> source tree :-)
I agree with Simon here.
I also think someone else found a similar fix and proposed a patch
already which is here:
https://lore.kernel.org/all/20260729-b4-android-bootmeth-oob-v1-1-31c3450ae0be@byteray.co.uk/
If you wish to contribute to U-Boot, please apply above patch and let us
know if that patch fixes the issue you've reported.
You can contribute by replying to above email using Tested-by:, for
example.
>
> Also I suggest avoiding HTML in email to the mailing list.
Yes, see:
https://docs.u-boot-project.org/en/latest/develop/sending_patches.html#general-patch-submission-rules
Thanks,
Mattijs
>
>>
>> Disclosure
>> ----------
>> This report follows a 90-day coordinated disclosure deadline. I'm happy to coordinate on the exact timing and to provide any further detail you need.
>>
>> Kind regards,
>> Arthur Chan
>>
>>
>>
>> ADA Logics Ltd is registered in England. No: 11624074.
>> Registered office: 266 Banbury Road, Post Box 292,
>> OX2 7DL, Oxford, Oxfordshire , United Kingdom
>
> Regards,
> Simon
prev parent reply other threads:[~2026-08-11 12:39 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 12:22 [security] Report of possible heap overflow in U-Boot's Android bootmeth before any AVB verification (ANT-2026-ZWED60S8) Arthur Chan
2026-08-06 14:52 ` Simon Glass
2026-08-11 12:39 ` Mattijs Korpershoek [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=871pc43k74.fsf@kernel.org \
--to=mkorpershoek@kernel.org \
--cc=adam@adalogics.com \
--cc=arthur.chan@adalogics.com \
--cc=david@adalogics.com \
--cc=security-cvd@anthropic.com \
--cc=sjg@chromium.org \
--cc=trini@konsulko.com \
--cc=u-boot@lists.u-boot-project.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.