From: Miquel Raynal <miquel.raynal@bootlin.com>
To: Griffin Kroah-Hartman <griffin@kroah.com>
Cc: Richard Weinberger <richard@nod.at>,
Vignesh Raghavendra <vigneshr@ti.com>,
linux-mtd@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] mtd: parsers: afs: add size check to v2 partition
Date: Tue, 25 Aug 2026 15:42:35 +0200 [thread overview]
Message-ID: <87cxv6gvuc.fsf@bootlin.com> (raw)
In-Reply-To: <20260824-mtd_break_looper-v1-1-e46d7f02faab@kroah.com> (Griffin Kroah-Hartman's message of "Mon, 24 Aug 2026 15:50:27 +0200")
Hello Griffin,
Thanks for the patch!
On 24/08/2026 at 15:50:27 +02, Griffin Kroah-Hartman <griffin@kroah.com> wrote:
> Add a size check to the loop in afs_parse_v2_partition(), avoiding
> walking out of the imginfo[] array bounds if a malicious packet fakes a
"packet" refers to network wording, whereas here, in the MTD world, we
would rather talk about a malicious image.
> large region count.
>
> Assisted-by: gkh_clanker_t1000
> Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
I guess such a fix would require a Fixes tag, as well as Cc'ing the
stable@vger.kernel.org alias.
> ---
> drivers/mtd/parsers/afs.c | 12 +++++++++---
> 1 file changed, 9 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/mtd/parsers/afs.c b/drivers/mtd/parsers/afs.c
> index 26116694c821..2c6f8768312c 100644
> --- a/drivers/mtd/parsers/afs.c
> +++ b/drivers/mtd/parsers/afs.c
> @@ -287,12 +287,18 @@ static int afs_parse_v2_partition(struct mtd_info *mtd,
> block_start, block_end);
>
> for (i = 0; i < region_count; i++) {
> - u32 region_load_addr = imginfo[pad + 3 + i*4];
> - u32 region_size = imginfo[pad + 4 + i*4];
> - u32 region_offset = imginfo[pad + 5 + i*4];
> + u32 region_load_addr;
> + u32 region_size;
> + u32 region_offset;
> u32 region_start;
> u32 region_end;
>
> + if (pad + 5 + i*4 >= ARRAY_SIZE(imginfo))
> + break;
> + region_load_addr = imginfo[pad + 3 + i*4];
> + region_size = imginfo[pad + 4 + i*4];
> + region_offset = imginfo[pad + 5 + i*4];
> +
Looking at the code, I see that just above the loop there is an actual
check bailing out early in case the region count is overly big. In
practice:
- pad can only be 0, 1 or 2
- imginfo array size is 36
The check is:
if (region_count > (ARRAY_SIZE(imginfo) - pad - 3) / 4)
return -EINVAL;
And the loop goes at most through:
pad + 5 + (region_count - 1) * 4
So the only possibilities are:
pad | max(region_count) | max(index)
----+-------------------+-----------
0 | 8 | 33
1 | 8 | 34
2 | 7 | 31
It seems like none of those situations could actually lead to a
reachable/exploitable bug. So while I understand the wish for a more
defensive hardening, the check you add seems redundant. I would
therefore suggest to just keep the driver as-is.
Thanks,
Miquèl
______________________________________________________
Linux MTD discussion mailing list
http://lists.infradead.org/mailman/listinfo/linux-mtd/
WARNING: multiple messages have this Message-ID (diff)
From: Miquel Raynal <miquel.raynal@bootlin.com>
To: Griffin Kroah-Hartman <griffin@kroah.com>
Cc: Richard Weinberger <richard@nod.at>,
Vignesh Raghavendra <vigneshr@ti.com>,
linux-mtd@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] mtd: parsers: afs: add size check to v2 partition
Date: Tue, 25 Aug 2026 15:42:35 +0200 [thread overview]
Message-ID: <87cxv6gvuc.fsf@bootlin.com> (raw)
In-Reply-To: <20260824-mtd_break_looper-v1-1-e46d7f02faab@kroah.com> (Griffin Kroah-Hartman's message of "Mon, 24 Aug 2026 15:50:27 +0200")
Hello Griffin,
Thanks for the patch!
On 24/08/2026 at 15:50:27 +02, Griffin Kroah-Hartman <griffin@kroah.com> wrote:
> Add a size check to the loop in afs_parse_v2_partition(), avoiding
> walking out of the imginfo[] array bounds if a malicious packet fakes a
"packet" refers to network wording, whereas here, in the MTD world, we
would rather talk about a malicious image.
> large region count.
>
> Assisted-by: gkh_clanker_t1000
> Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
I guess such a fix would require a Fixes tag, as well as Cc'ing the
stable@vger.kernel.org alias.
> ---
> drivers/mtd/parsers/afs.c | 12 +++++++++---
> 1 file changed, 9 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/mtd/parsers/afs.c b/drivers/mtd/parsers/afs.c
> index 26116694c821..2c6f8768312c 100644
> --- a/drivers/mtd/parsers/afs.c
> +++ b/drivers/mtd/parsers/afs.c
> @@ -287,12 +287,18 @@ static int afs_parse_v2_partition(struct mtd_info *mtd,
> block_start, block_end);
>
> for (i = 0; i < region_count; i++) {
> - u32 region_load_addr = imginfo[pad + 3 + i*4];
> - u32 region_size = imginfo[pad + 4 + i*4];
> - u32 region_offset = imginfo[pad + 5 + i*4];
> + u32 region_load_addr;
> + u32 region_size;
> + u32 region_offset;
> u32 region_start;
> u32 region_end;
>
> + if (pad + 5 + i*4 >= ARRAY_SIZE(imginfo))
> + break;
> + region_load_addr = imginfo[pad + 3 + i*4];
> + region_size = imginfo[pad + 4 + i*4];
> + region_offset = imginfo[pad + 5 + i*4];
> +
Looking at the code, I see that just above the loop there is an actual
check bailing out early in case the region count is overly big. In
practice:
- pad can only be 0, 1 or 2
- imginfo array size is 36
The check is:
if (region_count > (ARRAY_SIZE(imginfo) - pad - 3) / 4)
return -EINVAL;
And the loop goes at most through:
pad + 5 + (region_count - 1) * 4
So the only possibilities are:
pad | max(region_count) | max(index)
----+-------------------+-----------
0 | 8 | 33
1 | 8 | 34
2 | 7 | 31
It seems like none of those situations could actually lead to a
reachable/exploitable bug. So while I understand the wish for a more
defensive hardening, the check you add seems redundant. I would
therefore suggest to just keep the driver as-is.
Thanks,
Miquèl
next prev parent reply other threads:[~2026-08-25 13:43 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 13:50 [PATCH] mtd: parsers: afs: add size check to v2 partition Griffin Kroah-Hartman
2026-08-24 13:50 ` Griffin Kroah-Hartman
2026-08-25 13:42 ` Miquel Raynal [this message]
2026-08-25 13:42 ` Miquel Raynal
2026-08-25 14:05 ` Griffin Kroah-Hartman
2026-08-25 14:05 ` Griffin Kroah-Hartman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87cxv6gvuc.fsf@bootlin.com \
--to=miquel.raynal@bootlin.com \
--cc=griffin@kroah.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mtd@lists.infradead.org \
--cc=richard@nod.at \
--cc=vigneshr@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.