On Wed, 08 Jul 2026 20:03:04 +0530, Naveen Kumar Chaudhary wrote:

> The bounds check in do_rw() was written as:
> 
>     if (cnt + blk > limit)
> 
> with cnt and blk declared as uint (unsigned int) and limit as ulong.
> C's usual arithmetic conversions are applied per binary operator, so
> "cnt + blk" is evaluated entirely in unsigned int and wraps modulo
> 2^32 before the result is widened for the comparison against limit.
> With cnt = 0xFFFFFFFF and blk = 1 the sum wraps to 0 and the guard
> passes, allowing blk_dread()/blk_dwrite() to be issued with a 4 GiB
> transfer count that runs past the partition (or, when no partition
> is selected, the entire device).
> 
> [...]

Applied to u-boot/main, thanks!

[1/1] cmd: read: fix unsigned overflow bypassing range check
      commit: 1b8283bd3220e898d338fb98929f0b06ed63da84
-- 
Tom


Reply via email to