From patchwork Thu Mar 9 02:12:21 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Paul Liu X-Patchwork-Id: 661034 Delivered-To: patch@linaro.org Received: by 2002:adf:a3c6:0:0:0:0:0 with SMTP id m6csp80992wrb; Wed, 8 Mar 2023 18:12:59 -0800 (PST) X-Google-Smtp-Source: AK7set8q8oqekqFvmoPuHPTlBO+MBeCr9Covqa4DIwfpl7ICw7aM98kEKwiV0meOBy+tYDGeHa0z X-Received: by 2002:a05:6870:1398:b0:172:35ac:3be2 with SMTP id 24-20020a056870139800b0017235ac3be2mr9981926oas.6.1678327979644; Wed, 08 Mar 2023 18:12:59 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1678327979; cv=none; d=google.com; s=arc-20160816; b=Ja6r4iemsWBKPTxsWpuKVUwQ6vbSAmYWeK518GVCGmWIIItLawKGh0ZEX5lmAO5Hy4 8RR9i89K9jOJORCYQMet3Ynj/YUKzuQLRROI51Jve6jKwX9w/fnW7HqwKA9vys1KfjRm yphd05sEZ8NIz/Co3XhxBDLAW45G6QSFl3OuNfQR4xu/YKlJOizuhpnRLq2El1/HaiKD 3vh5F1A5Bh+oNlm22xJYu+JkfTMd1vZ/nTkyjPEDAxkthFZR3+53pKNgRIvynst6Sulg GTpPj8WSzAPzviauh8270cVV0mwKQe+0+1KnluedhNK4a+e3O+jZJzs5agVaEroEAvUY RbcA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:content-transfer-encoding :mime-version:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=VI8/K7FMkpFmPTtp5Z3C7jv7cmdTiYMKZOWfIt2cUfs=; b=JDOneFNN6NSnKJfm79fauvEh3+7Tnvxy5i73gKi5PcRDEGjVJ/hosSUyT2yngDBFtY kifZjYTy6F/SHSwFpTbOYkWStyBkHDf8ePLuqyLmsKD1kLtwSDUCF7gqHrm50pVEgF2z 91L/cYfyFKhztX++iQitXXR4F5cV2Sof9Q3ZoZB7flolj2eFg+6FdlgNXY+CtqUEQYI5 hApO/9vOkK1tdICLfhw4GMrr/zRNfsVxqJRqGn6vi//CNhpEPxqhZ0oD1X53rpJsSNJ1 aPJOeYDbJKBabC5Aovca4zfQzXOvvpOrfqHcWRArlaRllHlalYWXcHEgbFFbPm6zkcaS z/Gg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=JK5D5iTj; spf=pass (google.com: domain of u-boot-bounces@lists.denx.de designates 2a01:238:438b:c500:173d:9f52:ddab:ee01 as permitted sender) smtp.mailfrom=u-boot-bounces@lists.denx.de; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from phobos.denx.de (phobos.denx.de. [2a01:238:438b:c500:173d:9f52:ddab:ee01]) by mx.google.com with ESMTPS id 15-20020a056870120f00b001508c8f4da2si16582813oan.107.2023.03.08.18.12.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Mar 2023 18:12:59 -0800 (PST) Received-SPF: pass (google.com: domain of u-boot-bounces@lists.denx.de designates 2a01:238:438b:c500:173d:9f52:ddab:ee01 as permitted sender) client-ip=2a01:238:438b:c500:173d:9f52:ddab:ee01; Authentication-Results: mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=JK5D5iTj; spf=pass (google.com: domain of u-boot-bounces@lists.denx.de designates 2a01:238:438b:c500:173d:9f52:ddab:ee01 as permitted sender) smtp.mailfrom=u-boot-bounces@lists.denx.de; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: from h2850616.stratoserver.net (localhost [IPv6:::1]) by phobos.denx.de (Postfix) with ESMTP id 4B3CD85D9B; Thu, 9 Mar 2023 03:12:38 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de Authentication-Results: phobos.denx.de; dkim=pass (2048-bit key; unprotected) header.d=linaro.org header.i=@linaro.org header.b="JK5D5iTj"; dkim-atps=neutral Received: by phobos.denx.de (Postfix, from userid 109) id B690385DA6; Thu, 9 Mar 2023 03:12:36 +0100 (CET) X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de X-Spam-Level: X-Spam-Status: No, score=-2.1 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,SPF_HELO_NONE,SPF_PASS autolearn=ham autolearn_force=no version=3.4.2 Received: from mail-pj1-x1035.google.com (mail-pj1-x1035.google.com [IPv6:2607:f8b0:4864:20::1035]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by phobos.denx.de (Postfix) with ESMTPS id 0AE7B85D87 for ; Thu, 9 Mar 2023 03:12:31 +0100 (CET) Authentication-Results: phobos.denx.de; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: phobos.denx.de; spf=pass smtp.mailfrom=paul.liu@linaro.org Received: by mail-pj1-x1035.google.com with SMTP id qa18-20020a17090b4fd200b0023750b675f5so4514510pjb.3 for ; Wed, 08 Mar 2023 18:12:31 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1678327950; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=VI8/K7FMkpFmPTtp5Z3C7jv7cmdTiYMKZOWfIt2cUfs=; b=JK5D5iTj/l1JCZXCV/bJcdHFkqXw+UubJP8s8ZGBILQhdsO8g69jD9vxMMdH5uYmkm DXjQjeGNqWwnrnAsJTSj6Kvn6FEv9lRIBxgSqMK5QH9yKkPq/jWxb6cjSc+6hU2uw35O Ugfyop9N6uyInFeU22L0OXKj/SQ6mT566Img8GwH3Val1SxHr4KT9AqfGPjxUk/tViA7 jv8u3fJR5f2TIevIOk5Z+vw27qEeNoW5hORm19yJZFfIejneNsYqxfAQy6A5mVmdlwdH oayvy2FoPu2kFTq0IpnE6v47q4YbZIE2NEkukDp+Jgj4fE9vUNTkWhBnVzLXzgTZ71Bi o69Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1678327950; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=VI8/K7FMkpFmPTtp5Z3C7jv7cmdTiYMKZOWfIt2cUfs=; b=OHQNxOP5PhIaO5c7AM8Bt6wuNWaX4D1RsEFZCQinGMtPBMKSZb/k30/eGefkDYWIYB w0rKjtGralzJR+ip0HppE9nqIlYatXbIxrEPJ//01lh+Q1mgDgzaYgTfRiSegWBwuped tPsiAkLsIzWuitS7QFNnLcQEKuxkdVmlAcqKORHG21GXa5J0Xc2l+vdgEBh/int+XNp5 1Vk7v8Zc88JUH+PuwGT/Jbea8czZEU8EK/cW+iXu4LJb92kuT0Aao68lG05VNJZxufCK G4ODBhkJWero/igi3CxDIyU4k/c2/Htefg1v+pGloAuVwwSvtlXINT9JehP8oE5JwO4k yNDA== X-Gm-Message-State: AO0yUKXCRoYJYX9ElghZI2LXp/5BjMYh9YJj56/PVehklZVlV6M7zoWS mfLYHiBKscRhU/Pjo2sIboiPELRpEb9QAjcs6Mo= X-Received: by 2002:a05:6a20:be13:b0:cd:7040:10d4 with SMTP id ge19-20020a056a20be1300b000cd704010d4mr20057617pzb.62.1678327950261; Wed, 08 Mar 2023 18:12:30 -0800 (PST) Received: from localhost ([111.184.129.17]) by smtp.gmail.com with ESMTPSA id 202-20020a6301d3000000b00502e4015ff7sm9858324pgb.23.2023.03.08.18.12.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 08 Mar 2023 18:12:29 -0800 (PST) From: "Ying-Chun Liu (PaulLiu)" To: u-boot@lists.denx.de Cc: Tom Cherry , Ying-Chun Liu , Tom Rini Subject: [PATCH 1/1] lib/vsprintf.c: fix integer overflow in vsprintf Date: Thu, 9 Mar 2023 10:12:21 +0800 Message-Id: <20230309021221.306044-2-paul.liu@linaro.org> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20230309021221.306044-1-paul.liu@linaro.org> References: <20230309021221.306044-1-paul.liu@linaro.org> MIME-Version: 1.0 X-BeenThere: u-boot@lists.denx.de X-Mailman-Version: 2.1.39 Precedence: list List-Id: U-Boot discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: u-boot-bounces@lists.denx.de Sender: "U-Boot" X-Virus-Scanned: clamav-milter 0.103.8 at phobos.denx.de X-Virus-Status: Clean From: Tom Cherry vsnprintf_internal() adds 'size' to 'buf' and vsprintf() sets 'size' to 'INT_MAX' which can overflow. This causes sprintf() to fail when initializing the environment on 8GB. Instead of using 'INT_MAX', we use SIZE_MAX - buf, which is the largest possible string that could fit without overflowing 'size'. Signed-off-by: Tom Cherry [ Paul: pick from the Android tree. Rebase to the upstream ] Signed-off-by: Ying-Chun Liu (PaulLiu) Cc: Tom Rini Link: https://android.googlesource.com/platform/external/u-boot/+/43aae5d4415e0f9d744fb798acd52429d09957ce --- lib/vsprintf.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/lib/vsprintf.c b/lib/vsprintf.c index 2d13e68b57..cd89c56a8f 100644 --- a/lib/vsprintf.c +++ b/lib/vsprintf.c @@ -794,7 +794,12 @@ int scnprintf(char *buf, size_t size, const char *fmt, ...) */ int vsprintf(char *buf, const char *fmt, va_list args) { - return vsnprintf_internal(buf, INT_MAX, fmt, args); + /* vsnprintf_internal adds size to buf, so use a size that won't + * overflow. + */ + size_t max_size = SIZE_MAX - (size_t)buf; + + return vsnprintf_internal(buf, max_size, fmt, args); } int sprintf(char *buf, const char *fmt, ...)