Re: [U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-14 Thread Tom Rini
On Fri, Dec 14, 2018 at 02:06:38PM +0100, Simon Goldschmidt wrote: > On Tue, Dec 11, 2018 at 10:05 PM Simon Goldschmidt > wrote: > > > > Am 11.12.2018 um 21:10 schrieb Tom Rini: > > > On Tue, Dec 11, 2018 at 04:19:44PM +0100, Simon Goldschmidt wrote: > > >> Hi Tom, > > >> > > >> [truncated the CC

Re: [U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-14 Thread Simon Goldschmidt
On Tue, Dec 11, 2018 at 10:05 PM Simon Goldschmidt wrote: > > Am 11.12.2018 um 21:10 schrieb Tom Rini: > > On Tue, Dec 11, 2018 at 04:19:44PM +0100, Simon Goldschmidt wrote: > >> Hi Tom, > >> > >> [truncated the CC list a bit since I got "too many recipients" errors last > >> time] > >> > >> Am

Re: [U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-11 Thread Simon Goldschmidt
Am 11.12.2018 um 21:10 schrieb Tom Rini: On Tue, Dec 11, 2018 at 04:19:44PM +0100, Simon Goldschmidt wrote: Hi Tom, [truncated the CC list a bit since I got "too many recipients" errors last time] Am 11.12.2018 um 14:31 schrieb Tom Rini: On Sun, Dec 09, 2018 at 09:45:13PM +0100, Simon

Re: [U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-11 Thread Tom Rini
On Tue, Dec 11, 2018 at 04:19:44PM +0100, Simon Goldschmidt wrote: > Hi Tom, > > [truncated the CC list a bit since I got "too many recipients" errors last > time] > > Am 11.12.2018 um 14:31 schrieb Tom Rini: > >On Sun, Dec 09, 2018 at 09:45:13PM +0100, Simon Goldschmidt wrote: > > > >>This

Re: [U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-11 Thread Simon Goldschmidt
Hi Tom, [truncated the CC list a bit since I got "too many recipients" errors last time] Am 11.12.2018 um 14:31 schrieb Tom Rini: On Sun, Dec 09, 2018 at 09:45:13PM +0100, Simon Goldschmidt wrote: This series fixes CVE-2018-18440 ("insufficient boundary checks in filesystem image load") by

Re: [U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-11 Thread Tom Rini
On Sun, Dec 09, 2018 at 09:45:13PM +0100, Simon Goldschmidt wrote: > This series fixes CVE-2018-18440 ("insufficient boundary checks in > filesystem image load") by adding restrictions to the 'load' > command and fixes CVE-2018-18439 ("insufficient boundary checks in > network image boot") by

[U-Boot] [PATCH v5 0/9] Fix CVE-2018-18440 and CVE-2018-18439

2018-12-09 Thread Simon Goldschmidt
This series fixes CVE-2018-18440 ("insufficient boundary checks in filesystem image load") by adding restrictions to the 'load' command and fixes CVE-2018-18439 ("insufficient boundary checks in network image boot") by adding restrictions to the tftp code. The functions from lmb.c are used to