mirror of
https://github.com/apache/nuttx.git
synced 2026-08-24 15:08:47 +00:00
romfs_seek() clamps the computed position to the file size when it exceeds rf_size, but never checks for a negative result. lseek(fd, offset, SEEK_SET/SEEK_CUR/SEEK_END) with an offset that produces a negative position (e.g. a negative SEEK_SET offset, or a SEEK_CUR/ SEEK_END offset more negative than the current position/file size) is written straight into filep->f_pos. The subsequent romfs_read() computes `rf->rf_startoffset + filep->f_pos` into a uint32_t, so a negative f_pos wraps around to a huge unsigned offset, and romfs_hwread()'s XIP path memcpy()s from rm_xipbase plus that offset -- an out-of-bounds read far past the mapped flash region. Add the same "if (position < 0) return -EINVAL" guard already used by fs/fat/fs_fat32.c's seek function, before the existing end-of-file clamp. Signed-off-by: yi chen <94xhn1@gmail.com> Assisted-by: Claude:claude-sonnet-5 |
||
|---|---|---|
| .. | ||
| CMakeLists.txt | ||
| fs_romfs.c | ||
| fs_romfs.h | ||
| fs_romfsutil.c | ||
| Kconfig | ||
| Make.defs | ||