important · Boot chain
Debian's follow-up checks suggest U-Boot's filesystem-overflow fixes left SquashFS and ext4 validation gaps.
Affects
U-Boot, an embedded bootloader used across ARM and other embedded systems.
The available record says additional validation patches followed the original fixes, but it does not establish memory corruption on current upstream U-Boot.
Detail and 4 sources
Chain to watch
Retrieve Debian merge request 54's seven commits and isolate the two additional validation changes.→↓Exercise the associated malformed ext4 and SquashFS inputs against current upstream U-Boot under ASan and on representative boards.→↓Whether the remaining conditions corrupt memory on current upstream U-Boot and provide repeatable PC or LR control.
Unverified chainCompare the Debian changes with upstream, then run the malformed filesystem cases under ASan and on representative hardware.
Sources
ResearchBackport filesystem overflow fixes for 2025.01 (!54) · Merge requests · Debian / u-boot · GitLabResearchCVE-2025-70292ResearchRe: [PATCH v3 0/4] fix integer overflows in filesystem codeVendoross-security - Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293)