On Wed, Aug 05, 2026 at 08:43:59PM +0100, Arthur Chan wrote:

> Hello U-Boot (EFI Loader) maintainers,
> 
> I'd like to report a High-severity security issue in  U-Boot (EFI Loader) 
> (https://github.com/u-boot/u-boot / 
> https://git.u-boot-project.org/u-boot/u-boot) related to possible arbitrary 
> memory overwrite in U-Boot's EFI PE/COFF loader.
> 
> I have attached 3 files with this email as described below.
> 1) report.md: A full description of the vulnerability and how to reproduce 
> it, together with suggested fix of the issue.
> 2) Dockerfile: A Dockerfile for demonstrating the issue.
> 3) driver.c: Work with the Dockerfile to demonstrate the issue.
> 
> Attribution
> -----------
> Please attribute Claude and Ada Logics. This issue was found by Anthropic 
> from using agents to study security of open source projects, and I am from 
> Ada Logics helping validate the found issues and creating the report manually 
> and notify the maintainers.
> 
> Disclosure
> ----------
> This report follows a 90-day coordinated disclosure deadline. I'm happy to 
> coordinate on the exact timing and to provide any further detail you need.

So, this applies to all of the reports you've been generating. I want to
point again at
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=36d49bba19f2c19c933d13b25dcf4eb607a030b3
because these reports I believe fail most of the guidelines there. And
in short, addressing issues (and following
https://docs.u-boot.org/en/latest/develop/sending_patches.html) is much
more valuable than just passing on reports. Thanks.

-- 
Tom

Attachment: signature.asc
Description: PGP signature

Reply via email to