On 2026-07-29T19:02:09, Shahriyar Jalayeri <[email protected]> wrote:
> bootstd: android: bound the boot image read by its partition size
>
> read_slotted_partition() loads an Android boot/vendor_boot image into the
> load address, sizing the read from the image header:
>
>         num_blks = DIV_ROUND_UP(image_size, desc->blksz);
>         ...
>         blk_dread(desc, partition.start, num_blks, map_sysmem(addr, 0));
>
> image_size is priv->boot_img_size / priv->vendor_boot_img_size, taken from
> the boot image header and never bounded by the partition. A header
> claiming a size larger than the partition makes blk_dread read past the
> partition and write past the load buffer: an out-of-bounds write of
> attacker-controlled length on media a physical attacker can supply. It is
> reached during boot on a device where AVB does not gate the read (AVB
> disabled, or an unlocked device).
>
> Reject an image that does not fit in its partition before issuing the read.
> Both the boot and vendor_boot reads go through this function.
>
> Fixes: abadcda24b10 ("bootstd: android: don't read whole partition sizes")
> Signed-off-by: Shahriyar Jalayeri <[email protected]>
>
> boot/bootmeth_android.c | 8 ++++++++
>  1 file changed, 8 insertions(+)

Reviewed-by: Simon Glass <[email protected]>

Reply via email to