On Wed, 08 Jul 2026 20:03:04 +0530, Naveen Kumar Chaudhary wrote:
> The bounds check in do_rw() was written as:
>
> if (cnt + blk > limit)
>
> with cnt and blk declared as uint (unsigned int) and limit as ulong.
> C's usual arithmetic conversions are applied per binary operator, so
> "cnt + blk" is evaluated entirely in unsigned int and wraps modulo
> 2^32 before the result is widened for the comparison against limit.
> With cnt = 0xFFFFFFFF and blk = 1 the sum wraps to 0 and the guard
> passes, allowing blk_dread()/blk_dwrite() to be issued with a 4 GiB
> transfer count that runs past the partition (or, when no partition
> is selected, the entire device).
>
> [...]
Applied to u-boot/main, thanks!
[1/1] cmd: read: fix unsigned overflow bypassing range check
commit: 1b8283bd3220e898d338fb98929f0b06ed63da84
--
Tom