On 2026-07-29T19:02:09, Shahriyar Jalayeri <[email protected]> wrote: > bootstd: android: bound the boot image read by its partition size > > read_slotted_partition() loads an Android boot/vendor_boot image into the > load address, sizing the read from the image header: > > num_blks = DIV_ROUND_UP(image_size, desc->blksz); > ... > blk_dread(desc, partition.start, num_blks, map_sysmem(addr, 0)); > > image_size is priv->boot_img_size / priv->vendor_boot_img_size, taken from > the boot image header and never bounded by the partition. A header > claiming a size larger than the partition makes blk_dread read past the > partition and write past the load buffer: an out-of-bounds write of > attacker-controlled length on media a physical attacker can supply. It is > reached during boot on a device where AVB does not gate the read (AVB > disabled, or an unlocked device). > > Reject an image that does not fit in its partition before issuing the read. > Both the boot and vendor_boot reads go through this function. > > Fixes: abadcda24b10 ("bootstd: android: don't read whole partition sizes") > Signed-off-by: Shahriyar Jalayeri <[email protected]> > > boot/bootmeth_android.c | 8 ++++++++ > 1 file changed, 8 insertions(+)
Reviewed-by: Simon Glass <[email protected]>
