diff options
author | Simon Goldschmidt <simon.k.r.goldschmidt@gmail.com> | 2019-01-14 22:38:22 +0100 |
---|---|---|
committer | Tom Rini <trini@konsulko.com> | 2019-01-16 23:15:53 -0500 |
commit | a156c47e39ad7d007c88919103ee0ee131c6203b (patch) | |
tree | 10344e1016918d333cf38f540d3888b406235293 /configs/evb-px5_defconfig | |
parent | a85c213f4725fc097e28795d87136e05508ba70b (diff) |
tftp: prevent overwriting reserved memory
This fixes CVE-2018-18439 ("insufficient boundary checks in network
image boot") by using lmb to check for a valid range to store
received blocks.
Signed-off-by: Simon Goldschmidt <simon.k.r.goldschmidt@gmail.com>
Acked-by: Joe Hershberger <joe.hershberger@ni.com>
[trini: Always build lib/lmb.o on LMB and lib/fdtdec.o on OF_LIBFDT]
Signed-off-by: Tom Rini <trini@konsulko.com>
Diffstat (limited to 'configs/evb-px5_defconfig')
0 files changed, 0 insertions, 0 deletions