summaryrefslogtreecommitdiff
path: root/env/dataflash.c
diff options
context:
space:
mode:
authorTom Rini <trini@konsulko.com>2025-12-09 15:23:01 -0600
committerTom Rini <trini@konsulko.com>2025-12-12 08:52:57 -0600
commit87d85139a96a39429120cca838e739408ef971a2 (patch)
treec96752170ad31b02409c16624f1357b00fa3fe68 /env/dataflash.c
parent1b3050dfc4c466a06bd5ec5312d845244834eace (diff)
fs: fat: Perform sanity checks on getsize in get_fatent()HEADmaster
We do not perform a check on the value of getsize in get_fatent to ensure that it will fit within the allocated buffer. For safety sake, add a check now and if the value exceeds FATBUFBLOCKS use that value instead. While not currently actively exploitable, it was in the past so adding this check is worthwhile. This addresses CVE-2025-24857 and was originally reported by Harvey Phillips of Amazon Element55. Signed-off-by: Tom Rini <trini@konsulko.com>
Diffstat (limited to 'env/dataflash.c')
0 files changed, 0 insertions, 0 deletions