read_slotted_partition() loads an Android boot/vendor_boot image into the
load address, sizing the read from the image header:
num_blks = DIV_ROUND_UP(image_size, desc->blksz);
...
blk_dread(desc, partition.start, num_blks, map_sysmem(addr, 0));
image_size is priv->boot_img_size / priv->vendor_boot_img_size, taken from
the boot image header and never bounded by the partition. A header
claiming a size larger than the partition makes blk_dread read past the
partition and write past the load buffer: an out-of-bounds write of
attacker-controlled length on media a physical attacker can supply. It is
reached during boot on a device where AVB does not gate the read (AVB
disabled, or an unlocked device).
Reject an image that does not fit in its partition before issuing the read.
Both the boot and vendor_boot reads go through this function.
Fixes: abadcda24b10 ("bootstd: android: don't read whole partition sizes")
Signed-off-by: Shahriyar Jalayeri <[email protected]>
---
An out-of-bounds write in the Android bootmeth: read_slotted_partition()
sizes its blk_dread from the untrusted boot image header, so a header
claiming a size larger than the partition overruns the load buffer. Bound
the read by the partition size.
Based on v2026.07 (fdfe2ec48d5c). A reproducer is available on request.
---
boot/bootmeth_android.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/boot/bootmeth_android.c b/boot/bootmeth_android.c
index 1d70e8d5c05..4b58f850b20 100644
--- a/boot/bootmeth_android.c
+++ b/boot/bootmeth_android.c
@@ -384,6 +384,14 @@ static int read_slotted_partition(struct blk_desc *desc,
const char *const name,
if (ret < 0)
return log_msg_ret("part", ret);
+ /*
+ * The image size comes from the (untrusted) boot image header, so bound
+ * the read by the partition size: a valid image cannot be larger than
+ * the partition holding it.
+ */
+ if (num_blks > partition.size)
+ return log_msg_ret("image larger than partition", -EFBIG);
+
n = blk_dread(desc, partition.start, num_blks, map_sysmem(addr, 0));
if (n < num_blks)
return log_msg_ret("part read", -EIO);
---
base-commit: fdfe2ec48d5c1c2ed03073d73edd3fdd3fe1ffa1
change-id: 20260729-b4-android-bootmeth-oob-9abf16092595
Best regards,
--
Shahriyar Jalayeri <[email protected]>