]> git.ipfire.org Git - thirdparty/openwrt.git/commitdiff
mtd: fis: fix buffer overflow from negative memset size 23550/head
authorAnna Kiri <bredcorn@gmail.com>
Tue, 26 May 2026 17:10:36 +0000 (19:10 +0200)
committerJonas Jelonek <jelonek.jonas@gmail.com>
Fri, 17 Jul 2026 08:02:59 +0000 (10:02 +0200)
In fis_remap(), when desc < last, the memset size is computed as
'tmp - end'. Since tmp is calculated as 'end - positive_value', tmp is
always less than end, making 'tmp - end' negative. When cast to size_t,
this wraps to a very large value, causing a massive buffer overflow.

Fix by swapping the operands to 'end - tmp' which correctly computes the
number of bytes to clear.

Signed-off-by: Anna Kiri <bredcorn@gmail.com>
Link: https://github.com/openwrt/openwrt/pull/23550
Signed-off-by: Jonas Jelonek <jelonek.jonas@gmail.com>
package/system/mtd/src/fis.c

index 8f719901b801b404353a9a88f9ede37b247af851..936359e803987844290b4a77108d96bf55651669 100644 (file)
@@ -215,7 +215,7 @@ fis_remap(struct fis_part *old, int n_old, struct fis_part *new, int n_new)
                memmove(desc, last, end - tmp);
                if (desc < last) {
                        tmp = end - (last - desc) * sizeof(struct fis_image_desc);
-                       memset(tmp, 0xff, tmp - end);
+                       memset(tmp, 0xff, end - tmp);
                }
        }