diff options
author | Richard Weinberger <richard@nod.at> | 2024-07-31 18:07:54 +0200 |
---|---|---|
committer | Tom Rini <trini@konsulko.com> | 2024-08-15 14:35:31 -0600 |
commit | 1779a58c66a8229ebc18c08c11f9c7e71b3fd982 (patch) | |
tree | 99e25206ef738f37ae3db1ae4f06fd656602d382 /common/dlmalloc.c | |
parent | faf73fb70da91a5bccc8791be6dccdea99dee829 (diff) |
bootstage: Fix out-of-bounds read in reloc_bootstage()
bootstage_get_size() returns the total size of the data structure
including associated records.
When copying from gd->bootstage, only the allocation size of gd->bootstage
must be used. Otherwise too much memory is copied.
This bug caused no harm so far because gd->new_bootstage is always
large enough and reading beyond the allocation length of gd->bootstage
caused no problem due to the U-Boot memory layout.
Fix by using the correct size and perform the initial copy directly
in bootstage_relocate() to have the whole relocation process in the
same function.
Signed-off-by: Richard Weinberger <richard@nod.at>
Reviewed-by: Simon Glass <sjg@chromium.org>
Diffstat (limited to 'common/dlmalloc.c')
0 files changed, 0 insertions, 0 deletions