[PATCH] ubifs: fix out-of-bounds read in signature length check
Richard Weinberger
rw at kernel.org
Tue Aug 11 14:47:58 PDT 2026
On Fri, 24 Jul 2026 09:43:27 +0200, Ibrahim Hashimov wrote:
> ubifs_sb_verify_signature() bounds the on-disk ubifs_sig_node->len field
> before handing the signature payload to verify_pkcs7_signature(), but the
> check has the wrong sign:
>
> if (le32_to_cpu(signode->len) > snod->len + sizeof(struct ubifs_sig_node))
>
> The signature bytes start sizeof(struct ubifs_sig_node) (UBIFS_SIG_NODE_SZ,
> 64 bytes) into the node, so the payload is at most
>
> [...]
Applied, thanks!
[1/1] ubifs: fix out-of-bounds read in signature length check
commit: d68851fbac230fabaeeae25b19fe60ece173da88
More information about the linux-mtd
mailing list