On Sun, Aug 09, 2026 at 04:23:27AM +0000, Aristo Chen wrote:

> For a compressed kernel_noload image, bootm_load_os() allocates a
> per-image decompression buffer of ALIGN(image_len * 8, SZ_1M). The 8x
> multiplier is a heuristic: it comfortably covers what zstd and xz
> achieve on real kernels, but any well-compressed payload (say, a big
> run of zeros) can exceed it and fail decompression, and no fixed
> multiplier is safe against arbitrarily compressible input.
> 
> Read the real uncompressed size from the compressor header instead.
> Add a small helper image_decomp_get_uncompressed_size() that returns
> the uncompressed size when the format carries one: gzip ISIZE, lzma
> header uncompressed size, lz4 frame Content_Size when the FLG bit is
> set, and zstd Frame_Content_Size. Other formats return -EOPNOTSUPP.
> Bootm uses it to size the buffer to ALIGN(hdr_size, SZ_1M), capped at
> CONFIG_SYS_BOOTM_LEN because the value is attacker-controlled, and
> falls back to the 8x heuristic for formats without a size field
> (bzip2, lzo, xz) or when the header lacks the size (some lzma or lz4
> streams).

Have we gotten actual problem reports? This is a good bit of growth for
a problem I'm not sure we're seeing. Thanks.

-- 
Tom

Attachment: signature.asc
Description: PGP signature

Reply via email to