mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-01 18:50:34 +03:00
fix(ulp): validate bss_size before zeroing ULP BSS region
Crafted ULP binaries could specify a bss_size larger than the reserved memory, causing memset to zero past the ULP region boundary.
This commit is contained in:
@@ -154,6 +154,13 @@ esp_err_t ulp_load_binary(uint32_t load_addr, const uint8_t* program_binary, siz
|
||||
}
|
||||
|
||||
size_t text_data_size = header.text_size + header.data_size;
|
||||
if (text_data_size > CONFIG_ULP_COPROC_RESERVE_MEM - load_addr_bytes) {
|
||||
return ESP_ERR_INVALID_SIZE;
|
||||
}
|
||||
if ((size_t) header.bss_size > CONFIG_ULP_COPROC_RESERVE_MEM - load_addr_bytes - text_data_size) {
|
||||
return ESP_ERR_INVALID_SIZE;
|
||||
}
|
||||
|
||||
uint8_t* base = (uint8_t*) RTC_SLOW_MEM;
|
||||
|
||||
memcpy(base + load_addr_bytes, program_binary + header.text_offset, text_data_size);
|
||||
|
||||
Reference in New Issue
Block a user